ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
2
3
4
5
ProductReleasesPortProtocolSourceDestinationService DescriptionPurposeClassification
6
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23061433TCPApp Volumes ManagerDatabaseDefault port for Microsoft SQL.App Volumes Manager to SQL database.
7
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPApp Volumes ManagerESXiHostd.App Volumes Manager to vSphere ESXi hosts.
8
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPAdministrative console in browserApp Volumes Managerhttps://<App Volumes Manager Server FQDN>/Administrator access to App Volumes Manager admin console.
9
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPApp Volumes ManagervCenter ServerSOAP.App Volumes Manager to vCenter Server.
10
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306445TCPDynamic Environment Manager FlexEngineFile shares Dynamic Environment Manager agent access to SMB file shares.Virtual desktop or RDS host, to file shares.
11
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPApp Volumes AgentApp Volumes ManagerCan use port 80 if not using SSL certificates to secure communication.Virtual desktop or RDS host to App Volumes Manager.
12
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23065985TCPApp Volumes AgentApp Volumes ManagerPowerShell web services.Virtual desktop or RDS host to App Volumes Manager.
13
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230632111TCPHorizon ClientHorizon AgentOptional for USB redirection.
By default, USB traffic is side-channeled in the Blast Extreme or PCoIP ports indicated previously. If desired, this traffic can be separated onto the port indicated here.
USB redirection for an internal Horizon client device.Internal
14
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306389TCPHorizon AgentHorizon Connection ServerOnly required when doing an unmanaged agent registration, for example, RDSH agent install without linked-clone or instant-clone component.Unmanaged Horizon agent in virtual desktop or RDS host registration.
15
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064002TCPHorizon AgentHorizon Connection ServerJava Message Service (JMS) when using enhanced security (default).Java Message Service communication.
16
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172UDPHorizon ClientHorizon Connection ServerPCoIP traffic to PCoIP Secure Gateway.Tunneled Horizon client device display protocol session traffic via PCoIP Secure Gateway on Connection Server.Tunneled connection ports
17
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172TCPHorizon ClientHorizon Connection ServerPCoIP traffic to PCoIP Secure Gateway.Tunneled Horizon client device display protocol session initiation via PCoIP Secure Gateway on Connection Server.Tunneled connection ports
18
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068443TCPHorizon ClientHorizon Connection ServerBlast Extreme traffic to Blast Secure Gateway.Tunneled Horizon client device display protocol session traffic via Blast Secure Gateway on Connection Server.Tunneled connection ports
19
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon ClientHorizon Connection ServerLogin. SSL (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in certain cases. See HTTP Redirection in Horizon 7 in Horizon 7 Security.Can also carry tunneled RDP, client drive redirection, and USB redirection trafficTunnled Horizon client device login traffic.Tunneled connection ports
20
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon ClientUnified Access GatewayBlast Extreme via the Unified Access Gateway for data traffic where port sharing is used. This would be instead of TCP 8443.External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway.External
21
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064001TCPHorizon AgentHorizon Connection ServerJMS.Java Message Service communication.
22
Horizon7.10, 7.11, 7.12, 7.13, 8 2111, 8 2006, 8 2012, 8 2103, 8 2106, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172UDPHorizon ClientHorizon AgentPCoIP.Internal Horizon client device display protocol session traffic.Internal
23
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon ClientUnified Access GatewayLogin traffic. SSL (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in some cases. See HTTP Redirection in Horizon 7 in Horizon 7 Security. Can also carry tunneled RDP, client drive redirection, and USB redirection traffic.External Horizon client device login traffic via Unified Access Gateway.External
24
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172TCPHorizon ClientUnified Access Gateway PCoIP via PCoIP Secure Gateway on Unified Access Gateway.External Horizon client device display protocol session initiation via PCoIP Secure Gateway on Unified Access Gateway.External
25
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172UDPHorizon ClientUnified Access GatewayPCoIP via PCoIP Secure Gateway on Unified Access Gateway.External Horizon client device display protocol session traffic via PCoIP Secure Gateway on Unified Access Gateway.External
26
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443UDPHorizon ClientUnified Access GatewayBlast Extreme Network Intelligent Transport (BENIT) tries a UDP login connection if the client experiences difficulty making a TCP connection to the UAG.Optional for external Horizon client login traffic.External
27
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068443TCPHorizon ClientUnified Access Gateway
Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (performant channel). The Blast Secure Gateway on Unified Access Gateway includes Blast Extreme Adaptive Transport (BEAT) networking, which dynamically adjusts to network conditions such as varying speeds and packet loss. In Unified Access Gateway, you can configure the ports used by the BEAT protocol.

By default, Blast Extreme uses the standard ports TCP 8443 and UDP 8443.
However, port 443 can also be configured for Blast TCP.
The port configuration is set through the Unified Access Gateway Blast External URL property. See Blast TCP and UDP External URL Configuration Options.
If you configure Unified Access Gateway to use both IPv4 and IPv6 mode, then the Blast TCP/UDP must be set to port 443. You can enable Unified Access Gateway to act as a bridge for IPv6 Horizon clients to connet to an IPv4 backend Connection Server or agent environment. See Support for IPv4 and IPv6 Dual Mode for Horizon Infrastructure.
External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway.External
28
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068443UDPHorizon ClientUnified Access Gateway
Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (adaptive transport). The Blast Secure Gateway on Unified Access Gateway includes Blast Extreme Adaptive Transport (BEAT) networking, which dynamically adjusts to network conditions such as varying speeds and packet loss. In Unified Access Gateway, you can configure the ports used by the BEAT protocol.

By default, Blast Extreme uses the standard ports TCP 8443 and UDP 8443.
However, port 443 can also be configured for Blast TCP.
The port configuration is set through the Unified Access Gateway Blast External URL property. See Blast TCP and UDP External URL Configuration Options.
If you configure Unified Access Gateway to use both IPv4 and IPv6 mode, then the Blast TCP/UDP must be set to port 443. You can enable Unified Access Gateway to act as a bridge for IPv6 Horizon clients to connet to an IPv4 backend Connection Server or agent environment. See Support for IPv4 and IPv6 Dual Mode for Horizon Infrastructure.
External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway.External
29
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069427TCPHorizon ClientHorizon AgentOptional for client drive redirection (CDR) and multimedia redirection (MMR). By default, when using Blast Extreme, CDR traffic is side-channeled in the Blast Extreme ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here.Client drive redirection for an internal Horizon client device.Internal
30
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23063389TCPHorizon ClientHorizon AgentRDP.Internal Horizon client device display protocol session traffic.Internal
31
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172TCPHorizon ClientHorizon AgentPCoIP.Internal Horizon client device display protocol session initiation.Internal
32
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622443UDPHorizon ClientHorizon AgentBlast Extreme.Internal Horizon client device display protocol session traffic.Internal
33
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622443TCPHorizon ClientHorizon AgentBlast Extreme.Internal Horizon client device display protocol session traffic.Internal
34
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon ClientHorizon Connection ServerLogin traffic. SSL (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in some cases. See HTTP Redirection in Horizon 7 in Horizon 7 Security.Internal Horizon client login and authentication traffic.Internal
35
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068443 or 443TCPBrowserUnified Access GatewayHorizon 7 HTML Access.
8443 is the default but can be changed to 443 on the Unified Access Gateway.
External Horizon client login viaUnified Access Gateway.External
36
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230632111TCPUnified Access GatewayHorizon AgentOptional for USB redirection.

By default, USB traffic is side-channeled in the Blast Extreme or PCoIP ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here.
USB redirection for an external Horizon client device.External
37
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069427TCPUnified Access GatewayHorizon AgentOptional for client drive redirection (CDR) and multimedia redirection (MMR).

By default, when using Blast Extreme, CDR traffic is side-channeled in the Blast Extreme ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here.
Client drive redirection for an external Horizon client device.External
38
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23063389TCPUnified Access GatewayHorizon AgentRDP.External Horizon client device display protocol session traffic via Unified Access Gateway.External
39
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172UDPUnified Access GatewayHorizon AgentPCoIP.External Horizon client device display protocol session initiation via PCoIP Secure Gateway on Unified Access Gateway.External
40
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172TCPUnified Access GatewayHorizon AgentPCoIP.External Horizon client device display protocol session traffic via PCoIP Secure Gateway on Unified Access Gateway.External
41
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622443UDPUnified Access GatewayHorizon AgentBlast Extreme.External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway.External
42
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622443TCPUnified Access GatewayHorizon AgentBlast Extreme.External Horizon client device display protocol session traffic via Blast Secure Gateway on Unified Access Gateway.External
43
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230632111TCPHorizon Connection ServerHorizon AgentOptional for USB redirection for a tunneled connection.

By default, USB traffic is side-channeled in the Blast Extreme or PCoIP ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here.
Tunneled connection ports
44
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230632111TCPHorizon Connection ServerHorizon AgentFramework channel - used by ws_adminOne use is for vdmadmin to configure or read from agent.
For example, creating a Data Collection Tool (DCT) log bundle. (vdmadmin - A -getDCT...)
45
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069427TCPHorizon Connection ServerHorizon AgentOptional for client drive redirection (CDR) and multimedia redirection (MMR) for a tunneled connection.

By default, when using Blast Extreme, CDR traffic is side-channeled in the Blast Extreme ports indicated previously. If you prefer, this traffic can be separated onto the port indicated here.
Tunneled connection ports
46
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23063389TCPHorizon Connection ServerHorizon AgentRDP for a tunneled connection.RDP display protocol session traffic tunneled through Connection Server.Tunneled connection ports
47
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622443TCPHorizon Connection ServerHorizon AgentBlast Extreme for a tunneled connection.Blast display protocol session traffic tunneled through Connection Server.Tunneled connection ports
48
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172TCPHorizon Connection ServerHorizon AgentPCoIP for a tunneled connection.PCoIP display protocol session initiation tunneled through Connection Server.Tunneled connection ports
49
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064172UDPHorizon Connection ServerHorizon AgentPCoIP for a tunneled connection.PCoIP display protocol session traffic tunneled through Connection Server.Tunneled connection ports
50
Horizon8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069443TCPWeb Console in BrowserHorizon Recording Server[https://%3cRecording]https://<Recording Server FQDN or IP>:9443Administrator access to Horizon Recording Server web console.
51
Horizon8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069443TCPHorizon Recording ServerHorizon Recording ServerConfiguration import from one recording server to another.
52
Horizon8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306636TCPHorizon Recording ServerActive DirectoryLDAPSIf LDAPS is integrated with server for web console login.
53
Horizon8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23061443TCPHorizon Recording ServerMicrosoft SQL Server databaseMicrosoft SQL Server database (default port is 1433).Network ports for connections from a Horizon Recording Server to Microsfot SQL Server database.
54
Horizon8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23065432TCPHorizon Recording ServerPostgreSQL database
PostgreSQL database (default port is 5432).Network ports for connections from a Horizon Recording Server to PostgreSQL database.
55
Horizon8 2111, 8 2006, 8 2203, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069443TCPHorizon Recording AgentHorizon Recording ServerApplication Data over TLS.Recording data transmission.
56
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPAdministrative console in browservCenter Serverhttps://<vCenter Server FQDN>/Administrator access to vCenter Server vSphere Client.
57
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPAdministrative console in browserHorizon Connection Serverhttps://<Connection Server FQDN>/admin
https://<Connection Server FQDN>/newadmin
Administrator access to Horizon Connection Server admin console.
58
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306135TCPEnrollment ServerAD Certificate ServicesThe enrollment service uses TCP 135 RPC for the initial communication with the CA, then random port from 1024-5000 and 4192-65535.
See Certificate Services in https://support.microsoft.com/en-us/help/832017#method4
Enrollment server requests certificate from Microsoft Certificate Authority (CA) to generate a temporary, short-lived certificate.
59
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069443TCPAdministrative console in browserUnified Access Gatewayhttps://<Unified Access Gateway FQDN or IP Address>:9443/admin/Administrator access to Unified Access Gateway admin console.
60
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon Cloud ConnectorVMware Cloud Servicehttps://cloud.horizon.vmware.com Connection to VMware Cloud Service.
61
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon Cloud ConnectorHorizon Connection ServerIntegation of Horizon Cloud Connector to Horizon 7.
62
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23065500UDPHorizon Connection ServerRSA SecurID Authentication ManagerTwo-factor authentication. Default value is shown. This port is configurable.Allows integration to RSA SecurID for use as authentication method.
63
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068443TCPBrowserHorizon Connection ServerHorizon 7 HTML Access.Tunneled HTML client login and display protocol traffic.Tunneled connection ports
64
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068443TCPBrowserHorizon Connection ServerHorizon 7 HTML Access.Internal HTML client login and display protocol traffic.Internal
65
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306Enrollment ServerAD Domain ControllersEnrollment Server also communicates with the domain controllers, using all relevant ports to discover a DC and bind and query the Active Directory.See https://support.microsoft.com/en-us/help/832017#method1 and https://support.microsoft.com/en-us/help/832017#method12
66
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23065500UDPUnified Access GatewayRADIUSOther authentication sources such as RADIUS.

Default value for RADIUS is shown but is configurable.
Allows integration to RADIUS solution for use as authentication method.
67
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPUnified Access GatewayHorizon Connection ServerLogin.External Horizon client device login traffic via Unified Access Gateway.External
68
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306902TCPvCenter ServerESXiSOAPvCenter Server to vSphere ESXi hosts communication.
69
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPAdministrative console in browserHorizon Cloud ConnectorAdministrator access to Horizon Cloud Connector.
70
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPAdministrative console in browserHorizon Cloud ConnectorAdministrator access to Horizon Cloud Connector.
71
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 230632111TCPHorizon Connection ServerEnrollment serverFramework channelConnection Server to Enrollment Server communication.
72
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23061521TCPHorizon Connection ServerDatabaseIf using an Oracle database for events data.Horizon Connection Server to to Oracle database for events data.
73
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23061433TCPHorizon Connection ServerDatabaseIf using a Microsoft SQL database for events data (default port is 1433)Horizon Connection Server to to SQL database for events data.
74
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 230649152-65535TCPHorizon Connection ServerHorizon Connection ServerMS-RPC dynamic client port range. Required for Cloud Pod Architecture (CPA) LDAP communication.
75
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306135TCPHorizon Connection ServerHorizon Connection ServerMS-RPC endpoint mapper. Required for Cloud Pod Architecture (CPA) LDAP communication.
76
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23068472TCPHorizon Connection ServerHorizon Connection ServerCloud Pod Architecture inter-pod VIPA.Interpod communication in Cloud Pod Architecture.
77
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622636TCPHorizon Connection ServerHorizon Connection ServerCloud Pod Architecture ADLDS.Secure global LDAP replication.
78
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 230622389TCPHorizon Connection ServerHorizon Connection ServerCloud Pod Architecture ADLDS.Global LDAP replication.
79
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306389TCPHorizon Connection ServerHorizon Connection ServerUsed only during installation of a replica Horizon Connection Server.Connection Server to Connection Server communication.
80
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 230632111TCPHorizon Connection ServerHorizon Connection ServerCluster master secret.Used during installation of a replica Horizon Connection Server and when rekeying.
81
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064101TCPHorizon Connection ServerHorizon Connection ServerJMS SSL to replica Horizon Connection Server for redundancy and scale.Connection Server to Connection Server state data communication.
82
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23064100TCPHorizon Connection ServerHorizon Connection ServerJMS to replica Horizon Connection Server for redundancy and scale.Connection Server to Connection Server state data communication.
83
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon Connection ServervCenter ServerSOAP messages.Connection Server to vCenter Server communication.
84
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 23069443TCPHorizon Connection ServerUnified Access GatewayvRealize Operations for Horizon broker agent monitoring of UAG appliances.Monitoring of Unified Access Gateway with vRealize Operations.
85
Horizon7.10, 7.11, 7.12, 8 2006, 7.13, 8 2012, 8 2103, 8 2106, 8 2111, 8 2206, 8 2209, 8 2212, 8 2303, 8 2306443TCPHorizon Connection ServerApp Volumes ManagervRealize Operations for Horizon broker agent monitoring of App Volumes Managers.Monitoring of App Volumes Managers with vRealize Operations.
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100