Skip to main content

2026 年 10 月 8 日

Port and Protocol Requirements for Horizon Cloud on Google Cloud Platform Edge

Specific ports and protocols are required for deployment and ongoing operations of your Horizon Cloud on Google Cloud Platform environment. Configure the firewall rules described in this topic in your GCP VPC settings before deploying the Horizon Edge.

Note: Horizon Cloud on Google Cloud Platform is currently available in Limited Availability (LA) mode only.

Critical: Confirm that your internal network CIDRs do not overlap the following values used by Kubernetes inside the Edge Gateway VM:

  • Service CIDR: 192.168.236.0/23
  • Pod CIDR: 192.168.240.0/21

Management VPC Firewall Rules

Firewall RuleDirectionSource IPv4 RangeTargetsProtocols and Ports
Allow Edge to connect to UAG management console on port 9443. UAG uses the edge management subnet for NIC1.IngressCIDR range of the Management subnetAll instances in the networkTCP:9443
Allow desktop VM Horizon Agent to connect with MQTT on Edge and for SSO. Also required for internal Desktop VM connections.IngressCIDR range of the Desktop/tenant subnetAll instances in the networkTCP:31883, TCP:32443, UDP:31883
Allow Log collection and Diagnostic via SSH IAP.Ingress35.235.240.0/20 (Google's reserved range for IAP tunneling)All instances in the networkTCP:22
Allow east-west traffic for topology (UAG-to-UAG state reroute path). Required only if UAG is being deployed in Advanced mode with /28 subnet.IngressCIDR range of the UAG Management subnetAll instances in the networkUDP:8445

Desktop VPC Firewall Rules

Firewall RuleDirectionSource IPv4 RangeTargetsProtocols and Ports
Allow Internal passthrough Network Load Balancer health check ranges from Google Cloud probers. Required if UAG has an internal load balancer.Ingress130.211.0.0/22, 209.85.152.0/22 + Edge Management subnet CIDR (Required for Omnissa private LB IP monitoring)All instances in the network, or specify target tagsTCP:443
Allow internal users to connect to desktop VMs.IngressCIDR range of the desktop subnet / intranetAll instances in the networkTCP:80, TCP:443, TCP:8443, UDP:443, UDP:8443
Allow Log collection and Diagnostic via SSH IAP. Required if UAG is 2-NIC / Internal Only.Ingress35.235.240.0/20 (Google's reserved range for IAP tunneling)All instances in the networkTCP:22

Desktop VPC Firewall Rules (created by Horizon Cloud)

During pool provisioning (preparePool), Horizon Cloud creates one firewall rule per VPC referenced by the pool, targeting the pool's VMs via a network tag, to permit the Horizon display-protocol traffic (PCoIP, Blast, Side Channel; RDP/SSH only if enabled). If the firewall-management permissions (compute.firewalls.*, and for a Shared VPC the same permissions in the host project) are granted to the HCS service account, these rules are created automatically. If not, the customer admin must create equivalent rules manually.

Firewall RuleDirectionPrioritySource IPv4 RangeTargetsProtocols and Ports
Horizon display-protocol access to pool VMsIngress10000.0.0.0/0Pool VMs (HCS network tag)TCP:4172, UDP:4172 (PCoIP); TCP:9427 (Side Channel); TCP:22443, UDP:22443 (Blast)

DMZ VPC Firewall Rules

The DMZ VPC and its firewall rules are not required if you are deploying UAG in internal access mode only.

Firewall RuleDirectionPrioritySource IPv4 RangeTargetsProtocols and Ports
Allow external passthrough Network Load Balancer health check ranges from Google Cloud probers. Required if UAG has an external load balancer.Ingress100035.191.0.0/16, 209.85.152.0/22, 209.85.204.0/22All instances in the network, or specify target tagsTCP:443
Allow external users to connect to UAG.Ingress10000.0.0.0/0All instances in the network, or specify target tagsTCP:80 (HTTP), TCP:443 (HTTPS), TCP:8443 (Blast TCP), UDP:443 (Blast UDP), UDP:8443 (Blast UDP)
Allow Log collection and Diagnostic via SSH IAP.Ingress100035.235.240.0/20 (Google's reserved range for IAP tunneling)All instances in the network, or specify target tagsTCP:22

AD Server VPC Firewall Rules

Firewall RuleDirectionSource IPv4 RangeTargetsProtocols and Ports
Allow connectivity from Desktop VPC into AD VPCIngressDesktop VPC subnet CIDRAll instances in the networkTCP, UDP, ICMP
Allow connectivity from Management VPC into AD VPCIngressManagement VPC subnet CIDRAll instances in the networkTCP, UDP, ICMP
Allow GCP Cloud DNS to query AD DNS. Required for GCP infrastructure.Ingress35.199.192.0/19All instances in the networkTCP:53, UDP:53

Outbound Endpoint Requirements for Horizon Edge Gateway

In addition to the VPC firewall rules described above, the Horizon Edge Gateway and desktop VMs must be able to reach specific external HTTPS endpoints for control-plane communication, monitoring, software updates, and container registry access. Ensure that Cloud NAT is configured and that the following destinations are reachable from the Management VPC subnet.

SourceTargetPortsProtocolPurpose
Horizon Edge*.horizon.omnissa.com443TCPControl-plane communication. Region-specific service gateway endpoints.
Horizon EdgeDomain controllerKerberos: 88, LDAP: 389/3268, LDAPS: 636/3269TCP UDPRegistering Horizon Cloud with the domain, SSO login, and periodic discovery of domain controllers.
Horizon EdgeDNS server53, 853TCP UDPDNS services.
Horizon Edgesoftwareupdate.omnissa.com443TCPSoftware package server. Used for downloading updates of agent-related software used in image-related operations and the automated agent update process.
Horizon EdgeContainer registry (GCP Artifact Registry or equivalent)443TCPUsed for authentication and downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
Horizon Edge*.data.workspaceone.com443TCPTo send events or metrics to Workspace ONE Intelligence for monitoring data. Concrete endpoints include: eventproxy.na1.data.workspaceone.com, eventproxy.eu1.data.workspaceone.com, eventproxy.eu2.data.workspaceone.com, eventproxy.uk1.data.workspaceone.com, eventproxy.ca1.data.workspaceone.com, eventproxy.ap1.data.workspaceone.com, eventproxy.ap2.data.workspaceone.com, eventproxy.au1.data.workspaceone.com, eventproxy.in1.data.workspaceone.com.
Desktop (tenant) Subnet*.horizon.omnissa.com443TCP MQTTFor agent-related operations, such as certificate signing and renewal.
Desktop (tenant) SubnetDomain controllerKerberos: 88, LDAP: 389/3268, LDAPS: 636/3269TCP UDPLDAP/LDAPS services for VM-to-domain-controller connectivity. If the VDI is unable to reach any domain controller, session launch is not possible.
Desktop (tenant) SubnetDNS server53, 853TCP UDPDNS services.
Desktop (tenant) Subnetsoftwareupdate.omnissa.com443TCPSoftware package server. Used for downloading updates of agent-related software.
Desktop (tenant) Subneteventproxy.na1.data.workspaceone.com (and regional equivalents)443TCPUsed by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. Required only for DEX-enabled desktops.
Desktop (tenant) Subnetauth.na1.data.workspaceone.com (and regional equivalents)443TCPUsed by DEX telemetry agent to authenticate with Omnissa Intelligence. Required only for DEX-enabled desktops.

End-User Connection Traffic Ports and Protocols Requirements

To connect to their Horizon Cloud-provisioned virtual desktops and remote applications from their devices, your end users use a compatible installed Horizon Client or their browser using Horizon Web Client. The following ports must be opened for traffic from the end users' clients to reach their Horizon Cloud-provisioned virtual desktops and remote applications.

#SourceTargetPortPurpose
1Horizon Client / Browser*.horizon.omnissa.com443 TCPRegional Service Gateway redirect — after login, when the end user clicks to launch a desktop, traffic is redirected to UAG via the region-specific Service Gateway URL
2Horizon Client / Browsercloud.omnissahorizon.com443 TCPClient Access URL — required if the end user's own network is restricted/firewalled

App Volumes Ports and Protocols

To support App Volumes features for use with Horizon Cloud on Google Cloud Platform, you must configure port 445 for TCP protocol traffic to the tenant (desktops) subnet. Port 445 is the standard SMB port for accessing an SMB file share on Microsoft Windows. The AppStacks are stored in an SMB file share located in the same resource group as the Horizon Edge Gateway VMs.

Note: If you use a self-managed Active Directory, on-premises or in the cloud, to manage identities and devices, you can add a Google Cloud Filestore file system to the Active Directory domain. See Google Cloud documentation about using a self-managed Microsoft Active Directory.

Port Requirements for App Volumes

SourceTargetPortProtocolPurpose
App Volumes agent in the base imported VM, the golden images, desktop VMs, farm RDSH VMsThe IP address of the Google Cloud Filestore445TCPApp Volumes application virtualization on the VDI machines and application package capture on the VDI machines depend on access to the fileshares.

Cloud NAT Requirements

Cloud NAT must be attached to the following VPC subnets to enable the required outbound internet access.

VPCRequirementReason
Management VPCRequiredEdge VM requires internet access to download the latest module configurations from the Horizon Cloud control plane
Desktop VPCRequiredDesktop VM template requires internet access for agent pairing and OTP redemption with the connection service
DMZ VPCRequiredUAG VM requires internet access to retrieve bootstrap data from Horizon Cloud

VPC Peering Requirements

The following VPC peering connections must be configured before deployment. VPC peering is required in addition to firewall rules to allow traffic to flow between VPCs.

PeeringRequiredReason
Management VPC ↔ AD Server VPCRequiredEnables traffic flow between the Edge VM and the AD server VM
Desktop VPC ↔ Management VPCRequiredEnables SSO and MQTT telemetry path from desktop VMs to the Edge
Desktop VPC ↔ AD Server VPCRequiredEnables desktop VMs to reach the AD server for domain join
DMZ VPC ↔ Management VPCRequiredEnables the Edge VM to reach the UAG management console on port 9443 for Day 2 operations

DNS Configuration Requirements

Two GCP Cloud DNS zones must be configured before deployment to enable internal domain resolution from the Management and Desktop VPCs.

Zone TypeApplied ToPurpose
Forwarding zoneAD Server VPCForwards internal domain DNS queries from GCP Cloud DNS to the private IP of the AD server VM
DNS peering zoneManagement VPC and Desktop VPCForwards GCP Cloud DNS queries to the forwarding zone so that internal domain names resolve correctly from Edge and desktop VMs

After deploying the Horizon Edge Gateway and Unified Access Gateway, configure the required external DNS records as described in Configure DNS Records After Deploying Horizon Edge Gateway and Unified Access Gateway.

此頁面對您有幫助嗎?

針對本主題提供意見回饋

本主題對您有幫助嗎?

請勿填寫任何個人或機密資訊。

正在產生連結…