6.0.3

Table Of Contents
ESXi Firewall Concepts (hp://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_esxi_rewall_concepts)
The behavior of the NFS Client rule set (nfsClient) is dierent from other rule sets. When the NFS Client
rule set is enabled, all outbound TCP ports are open for the destination hosts in the list of allowed IP
addresses. See “NFS Client Firewall Behavior,” on page 177 for more information.
Manage ESXi Firewall Settings
You can congure incoming and outgoing rewall connections for a service or a management agent from
the vSphere Web Client or at the command line.
N If dierent services have overlapping port rules, enabling one service might implicitly enable other
services. You can specify which IP addresses are allowed to access each service on the host to avoid this
problem.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click the Manage tab and click .
3 Click Security .
The vSphere Web Client displays a list of active incoming and outgoing connections with the
corresponding rewall ports.
4 In the Firewall section, click Edit.
The display shows rewall rule sets, which include the name of the rule and the associated information.
5 Select the rule sets to enable, or deselect the rule sets to disable.
Column Description
Incoming Ports and Outgoing Ports
The ports that the vSphere Web Client opens for the service
Protocol
Protocol that a service uses.
Daemon
Status of daemons associated with the service
6 For some services, you can manage service details.
n
Use the Start, Stop, or Restart buons to change the status of a service temporarily.
n
Change the Startup Policy to have the service start with the host or with port usage.
7 For some services, you can explicitly specify IP addresses from which connections are allowed.
See Add Allowed IP Addresses for an ESXi Host,” on page 174.
8 Click OK.
Add Allowed IP Addresses for an ESXi Host
By default, the rewall for each service allows access to all IP addresses. To restrict trac, change each
service to allow trac only from your management subnet. You might also deselect some services if your
environment does not use them.
You can use the vSphere Web Client, vCLI, or PowerCLI to update the Allowed IP list for a service. By
default, all IP addresses are allowed for a service.
Adding Allowed IP Addresses to the ESXi Firewall
(hp://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_adding_allowed_IP_to_esxi_rewall)
vSphere Security
174 VMware, Inc.