6.0.2

Table Of Contents
Table 210. Incoming Firewall Connections (Continued)
Service Port Comment
NSX Distributed Logical Router
Service
6999 (UDP) NSX Virtual Distributed Router service. The
rewall port associated with this service is opened
when NSX VIBs are installed and the VDR module
is created. If no VDR instances are associated with
the host, the port does not have to be open.
This service was called NSX Distributed Logical
Router in earlier versions of the product.
Virtual SAN Transport 2233 (TCP) Virtual SAN reliable datagram transport. Uses
TCP and is used for Virtual SAN storage IO. If
disabled, Virtual SAN does not work.
SNMP Server 161 (UDP) Allows the host to connect to an SNMP server.
SSH Server 22 (TCP) Required for SSH access.
vMotion 8000 (TCP) Required for virtual machine migration with
vMotion.
vSphere Web Client 902, 443 (TCP) Client connections
vsanvp 8080 (TCP) VSAN VASA Vendor Provider. Used by the
Storage Management Service (SMS) that is part of
vCenter to access information about Virtual SAN
storage proles, capabilities, and compliance. If
disabled, Virtual SAN Storage Prole Based
Management (SPBM) does not work.
vSphere Web Access 80 (TCP) Welcome page, with download links for dierent
interfaces.
Table 211. Outgoing Firewall Connections
Service Port Comment
CIM SLP 427 (TCP, UDP) The CIM client uses the Service Location Protocol,
version 2 (SLPv2) to nd CIM servers.
DHCPv6 547 (TCP, UDP) DHCP client for IPv6.
DVSSync 8301, 8302 (UDP) DVSSync ports are used for synchronizing states
of distributed virtual ports between hosts that
have VMware FT record/replay enabled. Only
hosts that run primary or backup virtual machines
must have these ports open. On hosts that are not
using VMware FT these ports do not have to be
open.
HBR 44046, 31031 (TCP) Used for ongoing replication trac by vSphere
Replication and VMware Site Recovery Manager.
NFC 902 (TCP) Network File Copy (NFC) provides a le-type-
aware FTP service for vSphere components. ESXi
uses NFC for operations such as copying and
moving data between datastores by default.
WOL 9 (UDP) Used by Wake on LAN.
Virtual SAN Clustering Service 12345 23451 (UDP) Cluster Monitoring, Membership, and Directory
Service used by Virtual SAN.
DHCP Client 68 (UDP) DHCP client.
DNS Client 53 (TCP, UDP) DNS client.
Fault Tolerance 80, 8200, 8100, 8300 (TCP, UDP) Supports VMware Fault Tolerance.
Software iSCSI Client 3260 (TCP) Supports software iSCSI.
vSphere Upgrade
48 VMware, Inc.