View Agent (for Horizon 6), Horizon Agent (for Horizon 7), and Horizon Client use TCP and UDP ports for network access between each other and various View server components.

TCP and UDP Ports Used by View Agent or Horizon Agent
SourcePortTargetPortProtocolDescription
Horizon Client*View Agent/Horizon Agent3389TCPMicrosoft RDP traffic to View desktops if direct connections are used instead of tunnel connections.
Horizon Client*View Agent/Horizon Agent9427TCPWindows Media MMR redirection and client drive redirection, if direct connections are used instead of tunnel connections.
Note:Not needed for CDR when using VMware Blast Extreme.
Horizon Client*View Agent/Horizon Agent32111TCPUSB redirection and time zone synchronization if direct connections are used instead of tunnel connections.
Horizon Client*View Agent/Horizon Agent4172TCP and UDPPCoIP if PCoIP Secure Gateway is not used.
Note:Because the source port varies, see the note below this table.
Horizon Client*Horizon Agent22443TCP and UDPVMware Blast Extreme if direct connections are used instead of tunnel connections.
Note:UDP is not used on Linux desktops.
Browser*View Agent/Horizon Agent22443TCPHTML Access if direct connections are used instead of tunnel connections.
Security server, View Connection Server, or Access Point appliance*View Agent/Horizon Agent3389TCPMicrosoft RDP traffic to View desktops when tunnel connections are used.
Security server, View Connection Server, or Access Point appliance*View Agent/Horizon Agent9427TCPWindows Media MMR redirection and client drive redirection when tunnel connections are used.
Security server, View Connection Server, or Access Point appliance*View Agent/Horizon Agent32111TCPUSB redirection and time zone synchronization when tunnel connections are used.
Security server, View Connection Server, or Access Point appliance55000View Agent/Horizon Agent4172UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Security server, View Connection Server, or Access Point appliance*View Agent/Horizon Agent4172TCPPCoIP if PCoIP Secure Gateway is used.
Security server, View Connection Server, or Access Point appliance*Horizon Agent22443TCP and UDPVMware Blast Extreme if Blast Secure Gateway is used.
Note:UDP is not used on Linux desktops.
Security server, View Connection Server, or Access Point appliance*View Agent/Horizon Agent22443TCPHTML Access if Blast Secure Gateway is used.
View Agent/Horizon Agent*View Connection Server4001, 4002TCPJMS SSL traffic.
View Agent/Horizon Agent4172Horizon Client*UDPPCoIP, if PCoIP Secure Gateway is not used.
Note:Because the target port varies, see the note below this table.
View Agent/Horizon Agent4172View Connection Server, security server, or Access Point appliance55000UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Note:The UDP port number that agents use for PCoIP might change. If port 50002 is in use, the agent will pick 50003. If port 50003 is in use, the agent will pick port 50004, and so on. You must configure firewalls with ANY where an asterisk (*) is listed in the table.
TCP and UDP Ports Used by Horizon Client
SourcePortTargetPortProtocolDescription
Horizon Client*View Connection Server, security server, or Access Point appliance443TCPHTTPS for logging in to View. (This port is also used for tunnelling when tunnel connections are used.)
Note:Horizon Client 4.4 and later supports UDP port 443 (see below).
Horizon Client 4.4 or later*Access Point appliance 2.9 or later443UDP

HTTPS for logging into View, if Blast Secure Gateway is used and UDP Tunnel Server is enabled. (This port is also used for tunnelling when tunnel connections are used.)

Access Point appliance 2.9 or later443Horizon Client 4.4 or later*UDP

HTTPS for logging into View, if Blast Secure Gateway is used and UDP Tunnel Server is enabled. (This port is also used for tunnelling when tunnel connections are used.)

Horizon Client*View Agent/Horizon Agent22443TCPHTML Access and VMware Blast Extreme if Blast Secure Gateway is not used.
Horizon Client*Horizon Agent22443UDP

VMware Blast Extreme if Blast Secure Gateway is not used.

Note:Not used when connecting to Linux desktops.
Horizon Agent22443Horizon Client*UDP

VMware Blast Extreme if Blast Secure Gateway is not used.

Note:Not used when connecting to Linux desktops.
Horizon Client*View Agent/Horizon Agent3389TCPMicrosoft RDP traffic to View desktops if direct connections are used instead of tunnel connections.
Horizon Client*View Agent/Horizon Agent9427TCPWindows Media MMR redirection and client drive redirection, if direct connections are used instead of tunnel connections.
Note:Not needed for CDR when using VMware Blast Extreme.
Horizon Client*View Agent/Horizon Agent32111TCPUSB redirection and time zone synchronization if direct connections are used instead of tunnel connections.
Horizon Client*View Agent/Horizon Agent4172TCP and UDPPCoIP if PCoIP Secure Gateway is not used.
Note:Because the source port varies, see the note below this table.
Horizon Client*View Connection Server, security server, or Access Point appliance4172TCP and UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Note:Because the source port varies, see the note below this table.
View Agent/Horizon Agent4172Horizon Client*UDPPCoIP if PCoIP Secure Gateway is not used.
Note:Because the target port varies, see the note below this table.
Security server, View Connection Server, or Access Point appliance4172Horizon Client*UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Note:Because the target port varies, see the note below this table.
Horizon Client*View Connection Server, security server, or Access Point appliance8443TCPHTML Access and VMware Blast Extreme if Blast Secure Gateway is used.
Horizon Client*View Connection Server, security server, or Access Point appliance8443UDPVMware Blast Extreme if Blast Secure Gateway is used.
Note:Not used when connecting to a Linux desktop.
View Connection Server, security server, or Access Point appliance8443Horizon Client*UDPVMware Blast Extreme if Blast Secure Gateway is used.
Note:Not used when connecting to a Linux desktop.
Note:The UDP port number that clients use for PCoIP and VMware Blast Extreme might change. If port 50002 is in use, the client will pick 50003. If port 50003 is in use, the client will pick port 50004, and so on. You must configure firewalls with ANY where an asterisk (*) is listed in the table.