You'd need to open connections to
- Databricks web application
- Databricks secure cluster connectivity (SCC) relay
- AWS S3 global URL
- AWS S3 regional URL
- AWS STS global URL
- AWS STS regional URL
- AWS Kinesis regional URL
- Table metastore RDS regional URL (by data plane region)
in your firewall for the workspace to work.
More details could be found here