6.0.3

Table Of Contents
Table 56. Outgoing Firewall Connections (Continued)
Service Port Comment
Software iSCSI Client 3260 (TCP) Supports software iSCSI.
NSX Distributed Logical Router
Service
6999 (UDP) The rewall port associated with this service is
opened when NSX VIBs are installed and the VDR
module is created. If no VDR instances are
associated with the host, the port does not have to
be open.
rabbitmqproxy 5671 (TCP) A proxy running on the ESXi host that allows
applications running inside virtual machines to
communicate to the AMQP brokers running in the
vCenter network domain. The virtual machine
does not have to be on the network, that is, no NIC
is required. The proxy connects to the brokers in
the vCenter network domain. Therefore, the
outgoing connection IP addresses should at least
include the current brokers in use or future
brokers. Brokers can be added if customer would
like to scale up.
Virtual SAN Transport 2233 (TCP) Used for RDT trac (Unicast peer to peer
communication) between Virtual SAN nodes.
vMotion 8000 (TCP) Required for virtual machine migration with
vMotion.
VMware vCenter Agent 902 (UDP) vCenter Server agent.
vsanvp 8080 (TCP) Used for Virtual SAN Vendor Provider trac.
NFS Client Firewall Behavior
The NFS Client rewall rule set behaves dierently than other ESXi rewall rule sets. ESXi congures NFS
Client seings when you mount or unmount an NFS datastore. The behavior diers for dierent versions of
NFS.
When you add, mount, or unmount an NFS datastore, the resulting behavior depends on the version of
NFS.
NFS v3 Firewall Behavior
When you add or mount an NFS v3 datastore, ESXi checks the state of the NFS Client (nfsClient) rewall
rule set.
n
If the nfsClient rule set is disabled, ESXi enables the rule set and disables the Allow All IP Addresses
policy by seing the allowedAll ag to FALSE. The IP address of the NFS server is added to the allowed
list of outgoing IP addresses.
n
If the nfsClient rule set is enabled, the state of the rule set and the allowed IP address policy are not
changed. The IP address of the NFS server is added to the allowed list of outgoing IP addresses.
N If you manually enable the nfsClient rule set or manually set the Allow All IP Addresses policy,
either before or after you add an NFS v3 datastore to the system, your seings are overridden when the last
NFS v3 datastore is unmounted. The nfsClient rule set is disabled when all NFS v3 datastores are
unmounted.
When you remove or unmount an NFS v3 datastore, ESXi performs one of the following actions.
n
If none of the remaining NFS v3 datastores are mounted from the server of the datastore being
unmounted, ESXi removes the server's IP address from the list of outgoing IP addresses.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 177