The Citrix Workspace App ↔ VDA session uses both the classic ICA ports and the newer EDT ports by default in an internal deployment: * TCP 1494 The original ICA channel for unencrypted ICA traffic * TCP 2598 * The Session Reliability (CGP) channel over TCP when EDT isn't used or as a fallback UDP 2598 The Session Reliability channel over EDT (preferred UDP transport) * TCP 443 When Secure ICA (TLS) is enabled by default on newer VDAs, the ICA channel listens on port 443