6.0

Table Of Contents
3 In the Firewall section, click Properties.
The Firewall Properties dialog box lists all the rule sets that you can configure for the host.
4 Select the rule sets to enable, or deselect the rule sets to disable.
The Incoming Ports and Outgoing Ports columns indicate the ports that the vSphere Client opens for
the service. The Protocol column indicates the protocol that the service uses. The Daemon column
indicates the status of daemons associated with the service.
5 Click OK.
Add Allowed IP Addresses
You can specify which networks are allowed to connect to each service that is running on the host.
You can use the vSphere Client or the command line to update the Allowed IP list for a service. By default,
all IP addresses are allowed.
Procedure
1 Select the host in the inventory panel.
2 Click the Configuration tab and click Security Profile.
3 In the Firewall section, click Properties.
4 Select a service in the list and click Firewall.
5 Select Only allow connections from the following networks and enter the IP addresses of networks
that are allowed to connect to the host.
You can enter IP addresses in the following formats: 192.168.0.0/24, 192.168.1.2, 2001::1/64, or fd3e:
29a6:0a81:e478::/64.
6 Click OK.
Set Service or Client Startup Options
By default, daemon processes start when any of their ports are opened and stop when all of their ports are
closed. You can change this startup policy for the selected service or client.
Procedure
1 In the vSphere Client, select the host in the inventory.
2 Click the Configuration tab, then under Software click Security Profile.
3 In the Firewall section, click Properties.
All the firewall services and management agents that you can configure for the host are listed.
4 Select the service or management agent to configure and click Options.
You can set the service start policy, verify the status of the service, and manually start, stop, or restart
the service through this configuration.
5 Select a policy from the Startup Policy list.
6 Click OK.
vSphere Administration with the vSphere Client
60 VMware, Inc.