6.0.1

Table Of Contents
The behavior of the NFS Client rule set (nfsClient) is dierent from other rule sets. When the NFS Client
rule set is enabled, all outbound TCP ports are open for the destination hosts in the list of allowed IP
addresses.
The NFS 4.1 rule set opens outgoing connections to destination port 2049, which is the port named in the
specication for version 4.1 protocol. The outgoing connections are open for all IP addresses at the time of
the rst mount. This port remains open until the ESXi host is rebooted.
For more information about rewall congurations, see the vSphere Security documentation.
NFS Client Firewall Behavior
The NFS Client rewall rule set behaves dierently than other ESXi rewall rule sets. ESXi congures NFS
Client seings when you mount or unmount an NFS datastore. The behavior diers for dierent versions of
NFS.
When you add, mount, or unmount an NFS datastore, the resulting behavior depends on the version of
NFS.
NFS v3 Firewall Behavior
When you add or mount an NFS v3 datastore, ESXi checks the state of the NFS Client (nfsClient) rewall
rule set.
n
If the nfsClient rule set is disabled, ESXi enables the rule set and disables the Allow All IP Addresses
policy by seing the allowedAll ag to FALSE. The IP address of the NFS server is added to the allowed
list of outgoing IP addresses.
n
If the nfsClient rule set is enabled, the state of the rule set and the allowed IP address policy are not
changed. The IP address of the NFS server is added to the allowed list of outgoing IP addresses.
N If you manually enable the nfsClient rule set or manually set the Allow All IP Addresses policy,
either before or after you add an NFS v3 datastore to the system, your seings are overridden when the last
NFS v3 datastore is unmounted. The nfsClient rule set is disabled when all NFS v3 datastores are
unmounted.
When you remove or unmount an NFS v3 datastore, ESXi performs one of the following actions.
n
If none of the remaining NFS v3 datastores are mounted from the server of the datastore being
unmounted, ESXi removes the server's IP address from the list of outgoing IP addresses.
n
If no mounted NFS v3 datastores remain after the unmount operation, ESXi disables the nfsClient
rewall rule set.
NFS v4.1 Firewall Behavior
When you mount the rst NFS v4.1 datastore, ESXi enables the nfs41client rule set and sets its allowedAll
ag to TRUE. This action opens port 2049 for all IP addresses. Unmounting an NFS v4.1 datastore does not
aect the rewall state. That is, the rst NFS v4.1 mount opens port 2049 and that port remains enabled
unless you close it explicitly.
Verify Firewall Ports for NFS Clients
To enable access to NFS storage, ESXi automatically opens rewall ports for the NFS clients when you
mount an NFS datastore. For troubleshooting reasons, you might need to verify that the ports are open.
Procedure
1 In the vSphere Web Client, select the ESXi host.
2 Click the Manage tab, and click .
3 Select Security  in the System area, and click Edit.
vSphere Storage
156 VMware, Inc.