Consider your entire deployment, including how you integrate resources, when you make decisions about hardware, resources, and network requirements.
Supported vSphere and ESX Versions
The following versions of vSphere and ESXi servers are supported:
- 8.0, 7.0, 6.7, 6.5
Compatibility Between Omnissa Access Service and Connector
With the Omnissa Access on premises service, you can use supported connector versions that are either the same or earlier than the service version. For example, with the Omnissa Access 23.09 service, you can use the connector version 23.09 and earlier. You cannot use a connector version that is higher than the service version. For example, you cannot use the 23.09 connector with the 22.09 service. Using the latest compatible version of the connector is recommended.
For information on supported versions, see Omnissa Customer Connect.
Note: Omnissa Access connector 22.05 is not compatible with the on-premises Omnissa Access virtual appliance.
Hardware Sizing Requirements
Ensure that you meet the requirements for the number of Omnissa Access virtual appliances and the resources allocated to each appliance.
Note: For new deployments, the default Omnissa Access sizing requirements are as follows:
- 4vCPU
- 8 GB Memory
- 100 GB disk space
| Number of Users | Up to 1,000 | 1,000-10,000 | 10,000-25,000 | 25,000-50,000 | 50,000-100,000 |
|---|---|---|---|---|---|
| Number of Omnissa Access servers | 1 server | 3 load-balanced servers | 3 load-balanced servers | 3 load-balanced servers | 3 load-balanced servers |
| CPU (per server) | 4 CPU | 4 CPU | 4 CPU | 8 CPU | 8 CPU |
| RAM (per server) | 8 GB | 8 GB | 8 GB | 16 GB | 32 GB |
| Disk space (per server) | 100 GB | 100 GB | 100 GB | 100 GB | 100 GB |
Also, Ensure that you meet the requirements for the number of Omnissa Access connector instances. See Installing and Configuring Omnissa Access Connector.
Database Requirements
Set up Omnissa Access with the appropriate external database to store and organize server data.
The supported external databases are Microsoft SQL Server 2014, 2016, 2017, 2019, and 2022. For information about the Microsoft SQL database versions and service pack configurations supported, see the Omnissa Lifecycle Matrix.
The following database requirements apply. The exact specifications needed depend on the size and needs of your deployment.
| Number of Users | Up to 1,000 | 1,000-10,000 | 10,000-25,000 | 25,000-50,000 | 50,000-100,000 |
|---|---|---|---|---|---|
| CPU | 2 CPU | 2 CPU | 4 CPU | 8 CPU | 8 CPU |
| RAM | 4 GB | 4 GB | 8 GB | 16 GB | 32 GB |
| Disk space | 50 GB | 50 GB | 50 GB | 100 GB | 100 GB |
The SQL Server AlwaysOn capability is a combination of failover clustering and database mirroring, combined with log shipping for faster availability. AlwaysOn allows for multiple read copies of your database and a single read-write copy for operations. If your deployment environment has the bandwidth to support the traffic generated, the Omnissa Access database supports AlwaysOn.
Network Configuration Requirements
| Component | Minimum Requirement |
|---|---|
| DNS record and IP address | IP address and DNS record. |
| Firewall port | Ensure that the inbound firewall port 443 is open for users outside the network to the Omnissa Access instance or the load balancer. |
| Reverse Proxy | Deploy a reverse proxy such as F5 Access Policy Manager in the DMZ to allow users to access the Omnissa Access user portal remotely and securely. |
Unified Access Gateway 2.8 and later supports reverse proxy functionality to allow users to access the Omnissa Access unified catalog remotely and securely. Unified Access Gateway can be deployed in the DMZ behind the load balancers that is front-ending the Omnissa Access appliance.
Port Requirements
Ports used in the server configuration are described in the following table.
Your deployment might include only a subset of the listed ports. For example:
- To sync users and groups from Active Directory, Omnissa Access must connect to Active Directory.
- To sync with ThinApp, Omnissa Access must join the Active Directory domain and connect to the ThinApp Repository share.
Note: For Kerberos authentication port requirements see the Installing Omnissa Access Connector 23.09 guide, Network Requirement section.
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| 443 | HTTPS | Load Balancer | Omnissa Access machine | |
| 443 | HTTPS | Omnissa Access machine | Load Balancer | Required to validate the load balancer FQDN when it is set. |
| 443, 8443 | HTTPS/HTTP | Omnissa Access machine | Omnissa Access machine | For all Omnissa Access instances in a cluster, and across clusters in different data centers. |
| 443 | HTTPS | Browsers | Omnissa Access machine | |
| 443 | HTTPS | Omnissa Access machine | discovery.awmdm.com | Access for Workspace ONE Intelligent Hub application autodiscovery |
| 443 | HTTPS | Omnissa Access machine | *Please contact Support for the URL.* | Access to Cloud Catalog |
| 443 | HTTPS | Omnissa Access machine | signing.awmdm.com | Mandatory to launch Hub Services console and to provision certificates for Workspace ONE Notifications service. |
| 7443 | TCP | Browsers | Omnissa Access machine | SSL certificate authentication |
| 8443 | HTTPS | Browsers | Omnissa Access machine | Administrator Port |
| 25 | SMTP | Omnissa Access machine | SMTP | Port to relay outbound mail. |
| 389 636 3268 3269 | LDAP LDAPS MSFT-GC MSFT-GC-SSL | Omnissa Access machine | Active Directory | Default values are shown. These ports are configurable. |
| 445 | TCP | Omnissa Access machine | ThinApp repository | Access to the ThinApp repository. |
| 5555 | UDP | Omnissa Access machine | RSA SecurID server | Default value is shown. This port is configurable. |
| 53 | TCP/UDP | Omnissa Access machine | DNS server | Every virtual appliance must have access to the DNS server on port 53 and allow incoming SSH traffic on port 22. |
| 88, 464, 135, 445 | TCP/UDP | Omnissa Access machine | Domain controller | |
| 9300 | TCP | Omnissa Access machine | Omnissa Access machine | Audit needs. |
| 54328 | UDP | |||
| 5701 | TCP | Omnissa Access machine | Omnissa Access machine | Hazelcast cache. |
| 40002 40003 | TCP | Omnissa Access machine | Omnissa Access machine | Ehcache. |
| 1433 | TCP | Omnissa Access machine | Database | Microsoft SQL default port is 1433. |
| 443 | Omnissa Access machine | Horizon Connection Server | Access to Horizon Connection Server. | |
| 80, 443 | TCP | Omnissa Access machine | Integration Broker server | Connection to the Integration Broker. Port option depends on whether a certificate is installed on the Integration Broker server. |
| 443 | HTTPS | Omnissa Access | Workspace ONE UEM REST API | For device compliance checking and for the AirWatch Cloud Connector password authentication method, if that is used. |
| 88 | UDP | Unified Access Gateway | Omnissa Access machine | UDP port to open for mobile SSO. |
| 5262 | TCP | Android mobile device | Workspace ONE UEM HTTPS proxy service | Workspace ONE Tunnel client routes traffic to the HTTPS proxy for Android devices. |
| 88 | TCP/UDP | iOS mobile device | Omnissa Access machine | Port used for Kerberos traffic from iOS devices to the hosted cloud KDC service. |
| 443 | HTTPS/TCP | |||
| 514 | UDP | Omnissa Access machine | syslog server | UDP for external syslog server, if configured. |
Time Synchronization
Configuring time synchronization on all Omnissa Access service and connector instances is required for a Omnissa Access deployment to function correctly.
For information on configuring time synchronization for the Omnissa Access service, see Configuring Time Synchronization for the Omnissa Access Service.
For information on configuring time synchronization for the Omnissa Access connector, see Installing and Configuring Omnissa Access Connector.
Supported Directories
You integrate your enterprise directory with Omnissa Access and sync users and groups from your enterprise directory to the service.
-
The Active Directory environment can consist of a single Active Directory domain, multiple domains in a single Active Directory forest, or multiple domains across multiple Active Directory forests.
The Omnissa Access service supports Active Directory on Windows 2022, 2019, 2016, 2012 R2 with a Domain functional level and Forest functional level of Windows 2003 and later. A higher functional level might be required for some features. For example, to allow users to change Active Directory passwords from Workspace ONE, the Domain functional level must be Windows 2008 or later.
Supported Web Browsers to Access the Omnissa Access Console
The Omnissa Access console is a web-based application you use to manage the Omnissa Access service. You can access the Omnissa Access console from the latest versions of Mozilla Firefox, Google Chrome, Safari, and Microsoft Edge.
Supported Browsers to Access the Workspace ONE Intelligent Hub Portal
End users can access the Hub portal from the following browsers.
- Mozilla Firefox (latest)
- Google Chrome (latest)
- Safari (latest)
- Microsoft Edge browser
- Native browser and Google Chrome on Android devices
- Safari on iOS devices
Was this page helpful?