VMware Horizon uses TCP and UDP ports for network access between its components.
During installation, VMware Horizon can optionally configure Windows firewall rules to open the ports that are used by default. If you change the default ports after installation, you must manually reconfigure Windows firewall rules to allow access on the updated ports. See "Replacing Default Ports for VMware Horizon Services" in the Horizon Installation document.
For a list of ports that VMware Horizon uses for a certificate login associated with the TrueSSO solution, see VMware Horizon TrueSSO Ports.
Source | Port | Target | Port | Protocol | Description |
---|---|---|---|---|---|
Connection Server, or Unified Access Gateway appliance | 55000 | Horizon Agent | 4172 | UDP | PCoIP (not SALSA20) if PCoIP Secure Gateway is used. |
Connection Server, or Unified Access Gateway appliance | 4172 | Horizon Client | * | UDP | PCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Note: Because the target port varies, see the note below this table.
|
Connection Server, or Unified Access Gateway appliance | * | Horizon Agent | 3389 | TCP | Microsoft RDP traffic to VMware Horizon desktops when tunnel connections are used. |
Connection Server, or Unified Access Gateway appliance | * | Horizon Agent | 9427 | TCP | Windows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, VMware printer redirection, and USB redirection when tunnel connections are used. |
Connection Server, or Unified Access Gateway appliance | * | Horizon Agent | 32111 | TCP | USB redirection and time zone synchronization when tunnel connections are used. |
Connection Server, or Unified Access Gateway appliance | * | Horizon Agent | 4172 | TCP | PCoIP if PCoIP Secure Gateway is used. |
Connection Server, or Unified Access Gateway appliance | * | Horizon Agent | 22443 | TCP | VMware Blast Extreme if Blast Secure Gateway is used. |
Connection Server, or Unified Access Gateway appliance | * | Horizon Agent | 22443 | TCP | HTML Access if Blast Secure Gateway is used. |
Horizon Agent | 4172 | Horizon Client | * | UDP | PCoIP, if PCoIP Secure Gateway is not used.
Note: Because the target port varies, see the note below this table.
|
Horizon Agent | 4172 | Connection Server or Unified Access Gateway appliance | 55000 | UDP | PCoIP (not SALSA20) if PCoIP Secure Gateway is used. |
Horizon Agent | 4172 | Unified Access Gateway appliance | * | UDP | PCoIP. VMware Horizon desktops and applications send PCoIP data back to an Unified Access Gateway appliance from UDP port 4172 . The destination UDP port will be the source port from the received UDP packets and so as this is reply data, it is normally unnecessary to add an explicit firewall rule for this. |
Horizon Agent (unmanaged) | * | Connection server instance | 389 | TCP | AD LDS access during unmanaged agent installation.
Note: For other uses of this port, see the note below this table.
|
Horizon Client | * | Connection Server or Unified Access Gateway appliance | 80 | TCP | TLS (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in certain cases. See HTTP Redirection in VMware Horizon. |
Horizon Client | * | Connection Server or Unified Access Gateway appliance | 443 | TCP | HTTPS for logging in to VMware Horizon. (This port is also used for tunnelling when tunnel connections are used.) |
Horizon Client | * | Connection Server or Unified Access Gateway appliance | 4172 | TCP and UDP | PCoIP if PCoIP Secure Gateway is used. |
Horizon Client | * | Horizon Agent | 3389 | TCP | Microsoft RDP traffic to VMware Horizon desktops if direct connections are used instead of tunnel connections. |
Horizon Client | * | Horizon Agent | 9427 | TCP | Windows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, VMware printer redirection, and USB redirection, if direct connections are used instead of tunnel connections. |
Horizon Client | * | Horizon Agent | 32111 | TCP | USB redirection and time zone synchronization if direct connections are used instead of tunnel connections. |
Horizon Client | * | Horizon Agent | 4172 | TCP and UDP | PCoIP if PCoIP Secure Gateway is not used.
Note: Because the source port varies, see the note below this table.
|
Horizon Client | * | Horizon Agent | 22443 | TCP and UDP | VMware Blast |
Horizon Client | * | Connection Server or Unified Access Gateway appliance | 4172 | TCP and UDP | PCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Note: Because the source port varies, see the note below this table.
|
Web Browser | * | Unified Access Gateway appliance | 8443 | TCP | HTML Access. |
Connection Server | * | Connection Server | 48080 | TCP | For internal communication between Connection Server components. |
Connection Server | * | vCenter Server | 80 | TCP | SOAP messages if TLS is disabled for access to vCenter Servers. |
Connection Server | * | vCenter Server | 443 | TCP | SOAP messages if TLS is enabled for access to vCenter Servers. |
Connection Server | * | Connection Server | 4100 | TCP | JMS inter-router traffic. |
Connection Server | * | Connection Server | 4101 | TCP | JMS TLS inter-router traffic. |
Connection Server | * | Connection Server | 8472 | TCP | For interpod communication in Cloud Pod Architecture. |
Connection Server | * | Connection Server | 22389 | TCP | For global LDAP replication in Cloud Pod Architecture. |
Connection Server | * | Connection Server | 22636 | TCP | For secure global LDAP replication in Cloud Pod Architecture. |
Connection Server | * | Connection Server | 32111 | TCP | Key sharing traffic. |
Connection Server | * | Certificate Authority | * | HTTP, HTTPS | CRL or OCSP queries |
Unified Access Gateway appliance | * | Connection Server or load balancer | 443 | TCP | HTTPS access. Unified Access Gateway appliances connect on TCP port 443 to communicate with a Connection Server instance or load balancer in front of multiple Connection Server instances. |
Horizon Help Desk Tool | * | Horizon Agent | 3389 | TCP | Microsoft RDP traffic to Horizon desktops for Remote Assistance. |