Professional Documents
Culture Documents
NETWORK PORTS IN
VMWARE HORIZON 7
VMware Horizon 7 version 7.2
Table of Contents
About This Guide. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Client Connections. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Internal Connection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
External Connection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Tunneled Connection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Security Server. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
T E C H N I C A L W H I T E PA P E R | 2
NETWORK PORTS IN VMWARE HORIZON 7
Figure 1: Horizon 7 Network Ports with All Connection Types and All Display Protocols
Figure 1 shows three different client connection types and also includes all display protocols. Different
subsets of this diagram are displayed throughout this document and linked to larger PDF layouts. To
view these larger PDF diagram layouts, access the Attachments panel in this file or click on the diagram
images in the layout. You might need to download this PDF and view it locally (rather than in a browser)
for full interactive functionality.
Each subset of Figure 1 focuses on a particular connection type and display protocol use. The PDF
diagrams are high-resolution graphics and in a format suitable for printing as posters.
This document also contains tables that list all possible ports from a source component to destination
components. This does not mean that all of these ports necessarily need to be open. If a component or
display protocol is not in use, then the ports associated with it can be omitted. For example:
• If Blast Extreme is the only display protocol used, the PCoIP ports need not be opened.
• If VMware vRealize® Operations for Horizon is not deployed, ports to and from it can be ignored.
T E C H N I C A L W H I T E PA P E R | 3
NETWORK PORTS IN VMWARE HORIZON 7
The Horizon 7 tables and diagrams include connections to the following products, product families, and
components:
• vRealize Operations for Horizon
• VMware Horizon Client™
• VMware Identity Manager™
• VMware Unified Access Gateway™
• VMware App Volumes™
• VMware User Environment Manager™
• VMware vCenter Server®
• VMware ESXi™
• VMware AirWatch®
T E C H N I C A L W H I T E PA P E R | 4
NETWORK PORTS IN VMWARE HORIZON 7
Client Connections
Network ports for connections between a client (either Horizon Client or a browser) and the various
Horizon 7 components vary by whether the connections are internal, external, or tunneled.
Internal Connection
An internal connection is typically used within the internal network. Initial authentication is performed to
the View Connection Server, and then the Horizon Client connects directly to the Horizon Agent running
in the virtual desktop or RDS host.
The following table lists network ports for internal connections from a client device to Horizon 7
components. The diagrams following the table show network ports for internal connections, by display
protocol.
T E C H N I C A L W H I T E PA P E R | 5
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 6
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 7
NETWORK PORTS IN VMWARE HORIZON 7
External Connection
An external connection provides secure access into Horizon 7 resources from an external network.
A Unified Access Gateway or a security server provides the secure edge services. All communication from
the client will be to that edge device, which then communicates to the internal resources.
The following table lists network ports for external connections from a client device to Horizon 7
components. The diagrams following the table show network ports for external connections, by display
protocol, all with Unified Access Gateway.
Unified Access TCP 443 Blast Extreme via Blast Secure Gateway on
Gateway Unified Access Gateway for data traffic where
port sharing is used.
Excellent or typical network condition is
selected on client.
Unified Access TCP 443 VMware Identity Manager login and data traffic.
Gateway
T E C H N I C A L W H I T E PA P E R | 8
NETWORK PORTS IN VMWARE HORIZON 7
Figure 6: External Connection Showing All Display Protocols (Using Unified Access Gateway)
}}
T E C H N I C A L W H I T E PA P E R | 9
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 1 0
NETWORK PORTS IN VMWARE HORIZON 7
Tunneled Connection
A tunneled connection uses the View Connection Server to provide gateway services. Authentication
and session traffic is routed through the View Connection Server. This approach is less frequently used
because Unified Access Gateway can provide the same and more functionality.
The following table lists network ports for tunneled connections from a client device to the Horizon 7
components. The diagrams following the table show network ports for tunneled connections, by display
protocol.
T E C H N I C A L W H I T E PA P E R | 1 1
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 1 2
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 1 3
NETWORK PORTS IN VMWARE HORIZON 7
Horizon View TCP 4002 Java Message Service (JMS) when using
Agent Connection enhanced security (default).
Server
App Volumes App Volumes TCP 443 Can use port 80 if not using SSL certificates to
Agent Manager secure communication.
User File shares TCP 445 User Environment Manager agent access to
Environment SMB file shares.
Manager
FlexEngine
* VMware vRealize Operations for Horizon ports shown are for version 6.2. See the vRealize Operations
for Horizon Documentation for earlier versions.
T E C H N I C A L W H I T E PA P E R | 1 4
NETWORK PORTS IN VMWARE HORIZON 7
View Horizon Agent TCP 22443 Blast Extreme for a tunneled connection.
Connection
Server TCP 4172 PCoIP for a tunneled connection.
T E C H N I C A L W H I T E PA P E R | 1 5
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 1 6
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 1 7
NETWORK PORTS IN VMWARE HORIZON 7
Security Server
The following table lists network ports for connections from a security server to other Horizon 7
components. The diagrams following the table show network ports for external connections when using
a security server, by display protocol.
T E C H N I C A L W H I T E PA P E R | 1 8
NETWORK PORTS IN VMWARE HORIZON 7
Figure 14: External Connection Showing All Display Protocols (Using Security Server)
T E C H N I C A L W H I T E PA P E R | 1 9
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 2 0
NETWORK PORTS IN VMWARE HORIZON 7
TCP 443
Citrix TCP 80, 443 Connection to the Citrix Integration Broker. Port
Integration option depends on whether a certificate is
Broker server installed on the Integration Broker server.
RSA SecurID UDP 5500 Default value is shown. This port is configurable.
system
T E C H N I C A L W H I T E PA P E R | 2 1
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 2 2
NETWORK PORTS IN VMWARE HORIZON 7
Management
The following table lists network ports for the administrative consoles in Horizon 7.
App Volumes TCP 443 https:// <App Volumes Manager Server FQDN>/
Manager
T E C H N I C A L W H I T E PA P E R | 2 3
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 2 4
NETWORK PORTS IN VMWARE HORIZON 7
T E C H N I C A L W H I T E PA P E R | 2 5
NETWORK PORTS IN VMWARE HORIZON 7
The following people contributed their knowledge and assisted with reviewing:
• Frank Anderson, EUC Technical Marketing Architect, EUC Technical Marketing, VMware
• Mark Benson, Sr. Staff Engineer, EUC CTO Office, VMware
• Paul Green, Staff Engineer, Enterprise Desktop, VMware
• Andrew Jewitt, Staff Engineer, Enterprise Desktop, VMware
• Ramu Panayappan, Director, R&D, Enterprise Desktop, VMware
• Rick Terlep, EUC Architect, EUC Technical Marketing, VMware
• Jim Yanik, Senior Manager, EUC Technical Marketing, VMware
T E C H N I C A L W H I T E PA P E R | 2 6
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2017 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed
at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be
trademarks of their respective companies. Item No: VMW-TWP-NETWKPORTSHORIZ7-USLTR-20170908-WEB
9/17