Skip to main content

2025년 2월 19일

Firewall Rules for Client Web Browser Access

To allow client web browsers to make connections to Connection Server instances, remote desktops, and published applications, your firewalls must allow inbound traffic on certain TCP ports.

HTML Access connections must use HTTPS. HTTP connections are not allowed.

By default, when you install a Connection Server instance, the Horizon View Connection Server (Blast-In) rule is enabled in the Windows Firewall and the firewall is configured to allow inbound traffic to TCP port 8443.

Firewall Rules for Client Browser Access
SourceDefault Source PortProtocolTargetDefault Target PortNotes
Client web browserTCP AnyHTTPSConnection Server instanceTCP 443To make the initial connection, the web browser on a client device connects to a Connection Server instance on TCP port 443.
Client web browserTCP AnyHTTPSBlast Secure GatewayTCP 8443After the initial connection is made, the web browser on a client device connects to the Blast Secure Gateway on TCP port 8443. The Blast Secure Gateway must be enabled on a Connection Server instance to allow this second connection to take place.
Blast Secure GatewayTCP AnyHTTPSHTML Access AgentTCP 22443If the Blast Secure Gateway is enabled, after the user selects a remote desktop or published application, the Blast Secure Gateway connects to the HTML Access Agent on TCP port 22443 on the remote desktop virtual machine or RDS host. This agent component is included when you install Horizon Agent.
Client web browserTCP AnyHTTPSHTML Access AgentTCP 22443If the Blast Secure Gateway is not enabled, after the user selects a remote desktop or published application, the web browser on a client device makes a direct connection to the HTML Access Agent on TCP port 22443 on the remote desktop virtual machine or RDS host. This agent component is included when you install Horizon Agent.

이 페이지가 도움이 되었나요?

이 항목에 대한 피드백 보내기

이 항목이 도움이 되었나요?

개인정보나 기밀정보는 입력하지 마세요.

링크를 생성하는 중…