6.0.2

Table Of Contents
Table 211. Outgoing Firewall Connections (Continued)
Service Port Comment
NSX Distributed Logical Router
Service
6999 (UDP) The rewall port associated with this service is
opened when NSX VIBs are installed and the VDR
module is created. If no VDR instances are
associated with the host, the port does not have to
be open.
rabbitmqproxy 5671 (TCP) A proxy running on the ESXi host that allows
applications running inside virtual machines to
communicate to the AMQP brokers running in the
vCenter network domain. The virtual machine
does not have to be on the network, that is, no NIC
is required. The proxy connects to the brokers in
the vCenter network domain. Therefore, the
outgoing connection IP addresses should at least
include the current brokers in use or future
brokers. Brokers can be added if customer would
like to scale up.
Virtual SAN Transport 2233 (TCP) Used for RDT trac (Unicast peer to peer
communication) between Virtual SAN nodes.
vMotion 8000 (TCP) Required for virtual machine migration with
vMotion.
VMware vCenter Agent 902 (UDP) vCenter Server agent.
vsanvp 8080 (TCP) Used for Virtual SAN Vendor Provider trac.
vSphere DNS Requirements
You install or upgrade vCenter Server, like any other network server, on a host machine with a xed IP
address and well-known DNS name, so that clients can reliably access the service.
Assign a static IP address and host name to the Windows server that will host the vCenter Server system.
This IP address must have a valid (internal) domain name system (DNS) registration. When you install
vCenter Server and the Platform Services Controller, you must provide the fully qualied domain name
(FQDN) or the static IP of the host machine on which you are performing the install or upgrade. The
recommendation is to use the FQDN.
When you deploy the vCenter Server Appliance, you can assign a static IP to the appliance. This way, you
ensure that in case of system restart, the IP address of the vCenter Server Appliance remains the same.
Ensure that DNS reverse lookup returns an FQDN when queried with the IP address of the host machine on
which vCenter Server is installed. When you install or upgrade vCenter Server, the installation or upgrade
of the Web server component that supports the vSphere Web Client fails if the installer cannot look up the
fully qualied domain name of the vCenter Server host machine from its IP address. Reverse lookup is
implemented using PTR records.
If you use DHCP instead of a static IP address for vCenter Server, make sure that the vCenter Server
computer name is updated in the domain name service (DNS). If you can ping the computer name, the
name is updated in DNS.
Ensure that the ESXi host management interface has a valid DNS resolution from the vCenter Server and all
vSphere Web Client instances. Ensure that the vCenter Server has a valid DNS resolution from all ESXi hosts
and all vSphere Web Clients.
Chapter 2 Upgrade Requirements
VMware, Inc. 49