nerdexam
Broadcom-VMware

2V0-51.23 · Question #88

Drag and Drop Question Drag and drop the appropriate firewall ports in support of the Blast Extreme protocol into the correct locations in the diagram on the right. Two options will not be used. Answe

The correct answer is 4172 TCP/UDP; 443 TCP; 22443 TCP/UDP; 32111 TCP. VMware Horizon Blast Extreme Firewall Ports This question is from the VMware Horizon (VCP-EUC) exam domain and tests knowledge of which firewall ports the Blast Extreme display protocol requires, and what each one does. --- The Correct Ports and Why 1. 4172 TCP/UDP - Primary Blas

Section 1 – Horizon Architecture and Technologies

Question

Drag and Drop Question Drag and drop the appropriate firewall ports in support of the Blast Extreme protocol into the correct locations in the diagram on the right. Two options will not be used. Answer:

Exhibit

2V0-51.23 question #88 exhibit

Answer Area

Drag items

3389 TCP4172 TCP/UDP443 TCP8443 TCP/UDP22443 TCP/UDP32111 TCP

Correct arrangement

  • 4172 TCP/UDP
  • 443 TCP
  • 22443 TCP/UDP
  • 32111 TCP

Explanation

VMware Horizon Blast Extreme Firewall Ports

This question is from the VMware Horizon (VCP-EUC) exam domain and tests knowledge of which firewall ports the Blast Extreme display protocol requires, and what each one does.


The Correct Ports and Why

1. 4172 TCP/UDP - Primary Blast/PCoIP Display Channel

This port carries the main session display data. While 4172 is classically associated with PCoIP, VMware Horizon uses it in Blast Extreme deployments as the primary data tunnel port between the client and the edge device (UAG or Security Server). It goes first in the diagram because it represents the outermost client-facing connection - the first leg of traffic.

2. 443 TCP - HTTPS / Blast Secure Gateway (BSG)

Standard HTTPS port used for:

  • Initial authentication with the Connection Server
  • Blast Secure Gateway (BSG) tunneling when direct connections aren't possible
  • HTML Access (Blast delivered entirely via browser)

This sits second because after the client connects on 4172, management and tunneled traffic flows over 443 into the internal network segment.

3. 22443 TCP/UDP - Blast Extreme Adaptive Transport (BEAT)

This is the modern preferred Blast Extreme display port. It supports both TCP and UDP, dynamically selecting UDP when available for lower latency. It handles the actual pixel/display stream between the UAG/gateway and the virtual desktop agent. TCP/UDP dual support makes it resilient across varied network conditions.

4. 32111 TCP - USB Redirection

Used exclusively for USB device redirection over the Blast tunnel. It goes last because it's an ancillary/peripheral service, not part of the core display protocol path.


Why the Two Unused Items Are Excluded

PortWhy Not Used
3389 TCPThis is Microsoft RDP - a completely different display protocol. Blast Extreme does not use RDP.
8443 TCP/UDPThis is the original Blast Extreme direct connection port (client-to-agent, no gateway). The diagram depicts a tunneled/gateway deployment (via UAG), so 8443 is bypassed in favor of 22443 and 443.

Common Mistakes

  • Confusing 8443 and 22443: Many students pick 8443 because it's commonly listed as "the Blast port," but 8443 applies to direct (non-tunneled) connections. Exam diagrams with a UAG in the path use 22443 instead.
  • Thinking 3389 is needed: RDP and Blast Extreme are mutually exclusive protocol choices. Opening 3389 is only needed if you're using the RDP display protocol, not Blast.
  • Forgetting 32111: USB redirection is a distinct service requiring its own port - it doesn't piggyback on 443 or 22443.

Memory tip: 443 (auth/tunnel) → 22443 (display stream) → 32111 (USB) are the three Blast-specific ports to always remember. 4172 is the edge/gateway-facing data port shared with PCoIP infrastructure.

Topics

#Blast Extreme#firewall ports#display protocol#network ports

Community Discussion

No community discussion yet for this question.

Full 2V0-51.23 Practice