6.0.3

Table Of Contents
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click the Manage tab and click .
3 Under System, click Security .
4 In the Firewall section, click Edit and select a service from the list.
5 In the Allowed IP Addresses section, deselect Allow connections from any IP address and enter the IP
addresses of networks that are allowed to connect to the host.
Separate IP addresses with commas. You can use the following address formats:
n
192.168.0.0/24
n
192.168.1.2, 2001::1/64
n
fd3e:29a6:0a81:e478::/64
6 Click OK.
Incoming and Outgoing Firewall Ports for ESXi Hosts
The vSphere Web Client allows you to open and close rewall ports for each service or to allow trac from
selected IP addresses.
The following table lists the rewalls for services that are usually installed. If you install other VIBs on your
host, additional services and rewall ports might become available.
Table 55. Incoming Firewall Connections
Service Port Comment
CIM Server 5988 (TCP) Server for CIM (Common Information Model).
CIM Secure Server 5989 (TCP) Secure server for CIM.
CIM SLP 427 (TCP, UDP) The CIM client uses the Service Location Protocol,
version 2 (SLPv2) to nd CIM servers.
DHCPv6 546 (TCP, UDP) DHCP client for IPv6.
DVSSync 8301, 8302 (UDP) DVSSync ports are used for synchronizing states
of distributed virtual ports between hosts that
have VMware FT record/replay enabled. Only
hosts that run primary or backup virtual machines
must have these ports open. On hosts that are not
using VMware FT these ports do not have to be
open.
NFC 902 (TCP) Network File Copy (NFC) provides a le-type-
aware FTP service for vSphere components. ESXi
uses NFC for operations such as copying and
moving data between datastores by default.
Virtual SAN Clustering Service 12345, 23451 (UDP) Virtual SAN Cluster Monitoring and Membership
Directory Service. Uses UDP-based IP multicast to
establish cluster members and distribute Virtual
SAN metadata to all cluster members. If disabled,
Virtual SAN does not work.
DHCP Client 68 (UDP) DHCP client for IPv4.
DNS Client 53 (UDP) DNS client.
Fault Tolerance 8200, 8100, 8300 (TCP, UDP) Trac between hosts for vSphere Fault Tolerance
(FT).
Chapter 5 Securing ESXi Hosts
VMware, Inc. 175