| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | ||||||||||||||||||||||||||
2 | ||||||||||||||||||||||||||
3 | ||||||||||||||||||||||||||
4 | ||||||||||||||||||||||||||
5 | Product | Releases | Port | Protocol | Source | Destination | Service Description | Purpose | Classification | |||||||||||||||||
6 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 1433 | TCP | App Volumes Manager | Database | Default port for Microsoft SQL. | App Volumes Manager to SQL database. | ||||||||||||||||||
7 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | App Volumes Manager | ESXi | Hostd. | App Volumes Manager to vSphere ESXi hosts. | ||||||||||||||||||
8 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Administrative console in browser | App Volumes Manager | https://<App Volumes Manager Server FQDN>/ | Administrator access to App Volumes Manager admin console. | ||||||||||||||||||
9 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | App Volumes Manager | vCenter Server | SOAP. | App Volumes Manager to vCenter Server. | ||||||||||||||||||
10 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 445 | TCP | Dynamic Environment Manager FlexEngine | File shares | Dynamic Environment Manager agent access to SMB file shares. | Virtual desktop or RDS host, to file shares. | ||||||||||||||||||
11 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | App Volumes Agent | App Volumes Manager | Can use port 80 if not using SSL certificates to secure communication. | Virtual desktop or RDS host to App Volumes Manager. | ||||||||||||||||||
12 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 5985 | TCP | App Volumes Agent | App Volumes Manager | PowerShell web services. | Virtual desktop or RDS host to App Volumes Manager. | ||||||||||||||||||
13 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 32111 | TCP | Horizon Client | Horizon Agent | Optional for USB redirection. By default, USB traffic is side-channeled in the Blast Extreme or PCoIP ports indicated previously. If desired, this traffic can be separated onto the port indicated here. | USB redirection for an internal Horizon client device. | Internal | |||||||||||||||||
14 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 389 | TCP | Horizon Agent | Horizon Connection Server | Only required when doing an unmanaged agent registration, for example, RDSH agent install without linked-clone or instant-clone component. | Unmanaged Horizon agent in virtual desktop or RDS host registration. | ||||||||||||||||||
15 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4002 | TCP | Horizon Agent | Horizon Connection Server | Java Message Service (JMS) when using enhanced security (default). | Java Message Service communication. | ||||||||||||||||||
16 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | UDP | Horizon Client | Horizon Connection Server | PCoIP traffic to PCoIP Secure Gateway. | Tunneled Horizon client device display protocol session traffic via PCoIP Secure Gateway on Connection Server. | Tunneled connection ports | |||||||||||||||||
17 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | TCP | Horizon Client | Horizon Connection Server | PCoIP traffic to PCoIP Secure Gateway. | Tunneled Horizon client device display protocol session initiation via PCoIP Secure Gateway on Connection Server. | Tunneled connection ports | |||||||||||||||||
18 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8443 | TCP | Horizon Client | Horizon Connection Server | Blast Extreme traffic to Blast Secure Gateway. | Tunneled Horizon client device display protocol session traffic via Blast Secure Gateway on Connection Server. | Tunneled connection ports | |||||||||||||||||
19 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Client | Horizon Connection Server | Login. SSL (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in certain cases. See HTTP Redirection in Horizon 7 in Horizon 7 Security.Can also carry tunneled RDP, client drive redirection, and USB redirection traffic | Tunnled Horizon client device login traffic. | Tunneled connection ports | |||||||||||||||||
20 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Client | Unified Access Gateway | Blast Extreme via the Unified Access Gateway for data traffic where port sharing is used. This would be instead of TCP 8443. | External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
21 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4001 | TCP | Horizon Agent | Horizon Connection Server | JMS. | Java Message Service communication. | ||||||||||||||||||
22 | Horizon | 7.10, 7.11, 7.12, 7.13, 8 2111, 8 2006, 8 2012, 8 2103, 8 2106, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | UDP | Horizon Client | Horizon Agent | PCoIP. | Internal Horizon client device display protocol session traffic. | Internal | |||||||||||||||||
23 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Client | Unified Access Gateway | Login traffic. SSL (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in some cases. See HTTP Redirection in Horizon 7 in Horizon 7 Security. Can also carry tunneled RDP, client drive redirection, and USB redirection traffic. | External Horizon client device login traffic via Unified Access Gateway. | External | |||||||||||||||||
24 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | TCP | Horizon Client | Unified Access Gateway | PCoIP via PCoIP Secure Gateway on Unified Access Gateway. | External Horizon client device display protocol session initiation via PCoIP Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
25 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | UDP | Horizon Client | Unified Access Gateway | PCoIP via PCoIP Secure Gateway on Unified Access Gateway. | External Horizon client device display protocol session traffic via PCoIP Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
26 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | UDP | Horizon Client | Unified Access Gateway | Blast Extreme Network Intelligent Transport (BENIT) tries a UDP login connection if the client experiences difficulty making a TCP connection to the UAG. | Optional for external Horizon client login traffic. | External | |||||||||||||||||
27 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8443 | TCP | Horizon Client | Unified Access Gateway | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (performant channel). The Blast Secure Gateway on Unified Access Gateway includes Blast Extreme Adaptive Transport (BEAT) networking, which dynamically adjusts to network conditions such as varying speeds and packet loss. In Unified Access Gateway, you can configure the ports used by the BEAT protocol. By default, Blast Extreme uses the standard ports TCP 8443 and UDP 8443. However, port 443 can also be configured for Blast TCP. The port configuration is set through the Unified Access Gateway Blast External URL property. See Blast TCP and UDP External URL Configuration Options. If you configure Unified Access Gateway to use both IPv4 and IPv6 mode, then the Blast TCP/UDP must be set to port 443. You can enable Unified Access Gateway to act as a bridge for IPv6 Horizon clients to connet to an IPv4 backend Connection Server or agent environment. See Support for IPv4 and IPv6 Dual Mode for Horizon Infrastructure. | External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
28 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8443 | UDP | Horizon Client | Unified Access Gateway | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (adaptive transport). The Blast Secure Gateway on Unified Access Gateway includes Blast Extreme Adaptive Transport (BEAT) networking, which dynamically adjusts to network conditions such as varying speeds and packet loss. In Unified Access Gateway, you can configure the ports used by the BEAT protocol. By default, Blast Extreme uses the standard ports TCP 8443 and UDP 8443. However, port 443 can also be configured for Blast TCP. The port configuration is set through the Unified Access Gateway Blast External URL property. See Blast TCP and UDP External URL Configuration Options. If you configure Unified Access Gateway to use both IPv4 and IPv6 mode, then the Blast TCP/UDP must be set to port 443. You can enable Unified Access Gateway to act as a bridge for IPv6 Horizon clients to connet to an IPv4 backend Connection Server or agent environment. See Support for IPv4 and IPv6 Dual Mode for Horizon Infrastructure. | External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
29 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9427 | TCP | Horizon Client | Horizon Agent | Optional for client drive redirection (CDR) and multimedia redirection (MMR). By default, when using Blast Extreme, CDR traffic is side-channeled in the Blast Extreme ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here. | Client drive redirection for an internal Horizon client device. | Internal | |||||||||||||||||
30 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 3389 | TCP | Horizon Client | Horizon Agent | RDP. | Internal Horizon client device display protocol session traffic. | Internal | |||||||||||||||||
31 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | TCP | Horizon Client | Horizon Agent | PCoIP. | Internal Horizon client device display protocol session initiation. | Internal | |||||||||||||||||
32 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22443 | UDP | Horizon Client | Horizon Agent | Blast Extreme. | Internal Horizon client device display protocol session traffic. | Internal | |||||||||||||||||
33 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22443 | TCP | Horizon Client | Horizon Agent | Blast Extreme. | Internal Horizon client device display protocol session traffic. | Internal | |||||||||||||||||
34 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Client | Horizon Connection Server | Login traffic. SSL (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in some cases. See HTTP Redirection in Horizon 7 in Horizon 7 Security. | Internal Horizon client login and authentication traffic. | Internal | |||||||||||||||||
35 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8443 or 443 | TCP | Browser | Unified Access Gateway | Horizon 7 HTML Access. 8443 is the default but can be changed to 443 on the Unified Access Gateway. | External Horizon client login viaUnified Access Gateway. | External | |||||||||||||||||
36 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 32111 | TCP | Unified Access Gateway | Horizon Agent | Optional for USB redirection. By default, USB traffic is side-channeled in the Blast Extreme or PCoIP ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here. | USB redirection for an external Horizon client device. | External | |||||||||||||||||
37 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9427 | TCP | Unified Access Gateway | Horizon Agent | Optional for client drive redirection (CDR) and multimedia redirection (MMR). By default, when using Blast Extreme, CDR traffic is side-channeled in the Blast Extreme ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here. | Client drive redirection for an external Horizon client device. | External | |||||||||||||||||
38 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 3389 | TCP | Unified Access Gateway | Horizon Agent | RDP. | External Horizon client device display protocol session traffic via Unified Access Gateway. | External | |||||||||||||||||
39 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | UDP | Unified Access Gateway | Horizon Agent | PCoIP. | External Horizon client device display protocol session initiation via PCoIP Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
40 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | TCP | Unified Access Gateway | Horizon Agent | PCoIP. | External Horizon client device display protocol session traffic via PCoIP Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
41 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22443 | UDP | Unified Access Gateway | Horizon Agent | Blast Extreme. | External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
42 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22443 | TCP | Unified Access Gateway | Horizon Agent | Blast Extreme. | External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway. | External | |||||||||||||||||
43 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 32111 | TCP | Horizon Connection Server | Horizon Agent | Optional for USB redirection for a tunneled connection. By default, USB traffic is side-channeled in the Blast Extreme or PCoIP ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here. | Tunneled connection ports | ||||||||||||||||||
44 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 32111 | TCP | Horizon Connection Server | Horizon Agent | Framework channel - used by ws_admin | One use is for vdmadmin to configure or read from agent. For example, creating a Data Collection Tool (DCT) log bundle. (vdmadmin - A -getDCT...) | ||||||||||||||||||
45 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9427 | TCP | Horizon Connection Server | Horizon Agent | Optional for client drive redirection (CDR) and multimedia redirection (MMR) for a tunneled connection. By default, when using Blast Extreme, CDR traffic is side-channeled in the Blast Extreme ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here. | Tunneled connection ports | ||||||||||||||||||
46 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 3389 | TCP | Horizon Connection Server | Horizon Agent | RDP for a tunneled connection. | RDP display protocol session traffic tunneled through Connection Server. | Tunneled connection ports | |||||||||||||||||
47 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22443 | TCP | Horizon Connection Server | Horizon Agent | Blast Extreme for a tunneled connection. | Blast display protocol session traffic tunneled through Connection Server. | Tunneled connection ports | |||||||||||||||||
48 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | TCP | Horizon Connection Server | Horizon Agent | PCoIP for a tunneled connection. | PCoIP display protocol session initiation tunneled through Connection Server. | Tunneled connection ports | |||||||||||||||||
49 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4172 | UDP | Horizon Connection Server | Horizon Agent | PCoIP for a tunneled connection. | PCoIP display protocol session traffic tunneled through Connection Server. | Tunneled connection ports | |||||||||||||||||
50 | Horizon | 8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9443 | TCP | Web Console in Browser | Horizon Recording Server | [https://%3cRecording]https://<Recording Server FQDN or IP>:9443 | Administrator access to Horizon Recording Server web console. | ||||||||||||||||||
51 | Horizon | 8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9443 | TCP | Horizon Recording Server | Horizon Recording Server | Configuration import from one recording server to another. | |||||||||||||||||||
52 | Horizon | 8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 636 | TCP | Horizon Recording Server | Active Directory | LDAPS | If LDAPS is integrated with server for web console login. | ||||||||||||||||||
53 | Horizon | 8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 1443 | TCP | Horizon Recording Server | Microsoft SQL Server database | Microsoft SQL Server database (default port is 1433). | Network ports for connections from a Horizon Recording Server to Microsfot SQL Server database. | ||||||||||||||||||
54 | Horizon | 8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 5432 | TCP | Horizon Recording Server | PostgreSQL database | PostgreSQL database (default port is 5432). | Network ports for connections from a Horizon Recording Server to PostgreSQL database. | ||||||||||||||||||
55 | Horizon | 8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9443 | TCP | Horizon Recording Agent | Horizon Recording Server | Application Data over TLS. | Recording data transmission. | ||||||||||||||||||
56 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Administrative console in browser | vCenter Server | https://<vCenter Server FQDN>/ | Administrator access to vCenter Server vSphere Client. | ||||||||||||||||||
57 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Administrative console in browser | Horizon Connection Server | https://<Connection Server FQDN>/admin https://<Connection Server FQDN>/newadmin | Administrator access to Horizon Connection Server admin console. | ||||||||||||||||||
58 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 135 | TCP | Enrollment Server | AD Certificate Services | The enrollment service uses TCP 135 RPC for the initial communication with the CA, then random port from 1024-5000 and 4192-65535. See Certificate Services in https://support.microsoft.com/en-us/help/832017#method4 | Enrollment server requests certificate from Microsoft Certificate Authority (CA) to generate a temporary, short-lived certificate. | ||||||||||||||||||
59 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9443 | TCP | Administrative console in browser | Unified Access Gateway | https://<Unified Access Gateway FQDN or IP Address>:9443/admin/ | Administrator access to Unified Access Gateway admin console. | ||||||||||||||||||
60 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Cloud Connector | VMware Cloud Service | https://cloud.horizon.vmware.com | Connection to VMware Cloud Service. | ||||||||||||||||||
61 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Cloud Connector | Horizon Connection Server | Integation of Horizon Cloud Connector to Horizon 7. | |||||||||||||||||||
62 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 5500 | UDP | Horizon Connection Server | RSA SecurID Authentication Manager | Two-factor authentication. Default value is shown. This port is configurable. | Allows integration to RSA SecurID for use as authentication method. | ||||||||||||||||||
63 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8443 | TCP | Browser | Horizon Connection Server | Horizon 7 HTML Access. | Tunneled HTML client login and display protocol traffic. | Tunneled connection ports | |||||||||||||||||
64 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8443 | TCP | Browser | Horizon Connection Server | Horizon 7 HTML Access. | Internal HTML client login and display protocol traffic. | Internal | |||||||||||||||||
65 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | Enrollment Server | AD Domain Controllers | Enrollment Server also communicates with the domain controllers, using all relevant ports to discover a DC and bind and query the Active Directory. | See https://support.microsoft.com/en-us/help/832017#method1 and https://support.microsoft.com/en-us/help/832017#method12 | ||||||||||||||||||||
66 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 5500 | UDP | Unified Access Gateway | RADIUS | Other authentication sources such as RADIUS. Default value for RADIUS is shown but is configurable. | Allows integration to RADIUS solution for use as authentication method. | ||||||||||||||||||
67 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Unified Access Gateway | Horizon Connection Server | Login. | External Horizon client device login traffic via Unified Access Gateway. | External | |||||||||||||||||
68 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 902 | TCP | vCenter Server | ESXi | SOAP | vCenter Server to vSphere ESXi hosts communication. | ||||||||||||||||||
69 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Administrative console in browser | Horizon Cloud Connector | Administrator access to Horizon Cloud Connector. | |||||||||||||||||||
70 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Administrative console in browser | Horizon Cloud Connector | Administrator access to Horizon Cloud Connector. | |||||||||||||||||||
71 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 32111 | TCP | Horizon Connection Server | Enrollment server | Framework channel | Connection Server to Enrollment Server communication. | ||||||||||||||||||
72 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 1521 | TCP | Horizon Connection Server | Database | If using an Oracle database for events data. | Horizon Connection Server to to Oracle database for events data. | ||||||||||||||||||
73 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 1433 | TCP | Horizon Connection Server | Database | If using a Microsoft SQL database for events data (default port is 1433) | Horizon Connection Server to to SQL database for events data. | ||||||||||||||||||
74 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 49152-65535 | TCP | Horizon Connection Server | Horizon Connection Server | MS-RPC dynamic client port range. | Required for Cloud Pod Architecture (CPA) LDAP communication. | ||||||||||||||||||
75 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 135 | TCP | Horizon Connection Server | Horizon Connection Server | MS-RPC endpoint mapper. | Required for Cloud Pod Architecture (CPA) LDAP communication. | ||||||||||||||||||
76 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 8472 | TCP | Horizon Connection Server | Horizon Connection Server | Cloud Pod Architecture inter-pod VIPA. | Interpod communication in Cloud Pod Architecture. | ||||||||||||||||||
77 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22636 | TCP | Horizon Connection Server | Horizon Connection Server | Cloud Pod Architecture ADLDS. | Secure global LDAP replication. | ||||||||||||||||||
78 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 22389 | TCP | Horizon Connection Server | Horizon Connection Server | Cloud Pod Architecture ADLDS. | Global LDAP replication. | ||||||||||||||||||
79 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 389 | TCP | Horizon Connection Server | Horizon Connection Server | Used only during installation of a replica Horizon Connection Server. | Connection Server to Connection Server communication. | ||||||||||||||||||
80 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 32111 | TCP | Horizon Connection Server | Horizon Connection Server | Cluster master secret. | Used during installation of a replica Horizon Connection Server and when rekeying. | ||||||||||||||||||
81 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4101 | TCP | Horizon Connection Server | Horizon Connection Server | JMS SSL to replica Horizon Connection Server for redundancy and scale. | Connection Server to Connection Server state data communication. | ||||||||||||||||||
82 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 4100 | TCP | Horizon Connection Server | Horizon Connection Server | JMS to replica Horizon Connection Server for redundancy and scale. | Connection Server to Connection Server state data communication. | ||||||||||||||||||
83 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Connection Server | vCenter Server | SOAP messages. | Connection Server to vCenter Server communication. | ||||||||||||||||||
84 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 9443 | TCP | Horizon Connection Server | Unified Access Gateway | vRealize Operations for Horizon broker agent monitoring of UAG appliances. | Monitoring of Unified Access Gateway with vRealize Operations. | ||||||||||||||||||
85 | Horizon | 7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306 | 443 | TCP | Horizon Connection Server | App Volumes Manager | vRealize Operations for Horizon broker agent monitoring of App Volumes Managers. | Monitoring of App Volumes Managers with vRealize Operations. | ||||||||||||||||||
86 | ||||||||||||||||||||||||||
87 | ||||||||||||||||||||||||||
88 | ||||||||||||||||||||||||||
89 | ||||||||||||||||||||||||||
90 | ||||||||||||||||||||||||||
91 | ||||||||||||||||||||||||||
92 | ||||||||||||||||||||||||||
93 | ||||||||||||||||||||||||||
94 | ||||||||||||||||||||||||||
95 | ||||||||||||||||||||||||||
96 | ||||||||||||||||||||||||||
97 | ||||||||||||||||||||||||||
98 | ||||||||||||||||||||||||||
99 | ||||||||||||||||||||||||||
100 |