You mentioned the client which is the endpoint (e.g. Horizon Client, zero client, thin client) but then linked clones. When the Horizon Agent is installed on a linked clone it wants the firewall to be on (The service need to be running) so it can configure the exceptions. However, it's OK for the firewall to be off for Domain/Home or work/Public networks. The configuration of the Horizon Client (endpoint) doesn't matter as long as it can properly communicate.