Specifications

Table Of Contents
Table 212. Ports Required for Communication Between Components
Port Description
22 SSH Server (vSphere Client)
53 DNS Client
80 vCenter Server requires port 80 for direct HTTP connections. Port 80 redirects requests to HTTPS
port 443. This redirection is useful if you accidentally use http://server instead of https://server.
WS-Management (also requires port 443 to be open)
If you use a custom Microsoft SQL database (not the bundled SQL Server 2008 database) that is
stored on the same host machine as the vCenter Server, port 80 is used by the SQL Reporting Service.
When you install vCenter Server, the installer will prompt you to change the HTTP port for vCenter
Server. Change the vCenter Server HTTP port to a custom value to ensure a successful installation.
Microsoft Internet Information Services (IIS) also use port 80. See “Conflict Between vCenter Server
and IIS for Port 80,” on page 27.
88 Control interface RPC for Kerberos, used by vCenter Single Sign-On
111 RPC service that is used for the NIS register by the vCenter Server Appliance
123 NTP Client
135 Used to join vCenter Virtual Appliance to an Active Directory domain.
161 SNMP Server
389 This port must be open on the local and all remote instances of vCenter Server. This is the LDAP port
number for the Directory Services for the vCenter Server group. The vCenter Server system needs to
bind to port 389, even if you are not joining this vCenter Server instance to a Linked Mode group. If
another service is running on this port, it might be preferable to remove it or change its port to a
different port. You can run the LDAP service on any port from 1025 through 65535.
If this instance is serving as the Microsoft Windows Active Directory, change the port number from
389 to an available port from 1025 through 65535.
427 The CIM client uses the Service Location Protocol, version 2 (SLPv2) to find CIM servers.
443 The default port that the vCenter Server system uses to listen for connections from the vSphere
Client. To enable the vCenter Server system to receive data from the vSphere Client, open port 443 in
the firewall.
The vCenter Server system also uses port 443 to monitor data transfer from SDK clients.
This port is also used for the following services:
n
WS-Management (also requires port 80 to be open)
n
vSphere Client access to vSphere Update Manager
n
Third-party network management client connections to vCenter Server
n
Third-party network management clients access to hosts
513 vCenter Virtual Appliance used for logging activity
636 For vCenter Server Linked Mode, this is the SSL port of the local instance. If another service is
running on this port, it might be preferable to remove it or change its port to a different port. You can
run the SSL service on any port from 1025 through 65535.
902 The default port that the vCenter Server system uses to send data to managed hosts. Managed hosts
also send a regular heartbeat over UDP port 902 to the vCenter Server system. This port must not be
blocked by firewalls between the server and the hosts or between hosts.
Port 902 must not be blocked between the vSphere Client and the hosts. The vSphere Client uses this
port to display virtual machine consoles
903 Access a virtual machine console from the vSphere Client when the vSphere Client is connected
directly to the ESXi host (no vCenter Server).
MKS transactions (xinetd/vmware-authd-mks)
1234, 1235 vSphere Replication
2012 Control interface RPC for vCenter Single Sign-On vmdir.
2013 Control interface RPC for Kerberos, used by vCenter Single Sign-On
2014 RPC port for all VMCA (VMware Certificate Authority) APIs
vSphere Upgrade
24 VMware, Inc.