6.0

Table Of Contents
connected in the vCenter Server. If an administrator removes the VIB from a host, for example by using the
esxcli utility, the vSphere Replication appliance reinstalls the VIB the next time you restart the appliance or
when a host is restarted or reconnected to the inventory. If you do not want ports 10000 to 10010 to be open
on an ESXi host, and if you do not plan to use this host as a replication source, you can disable the
Replication-to-Cloud Traffic rule. See Allow or Deny Access to an ESXi Service or Management Agent with
the vSphere Web Client.
To reduce the number of open ports or to change the ports that are used for communication between ESXi
hosts and the vCloud Tunneling Agent, you can create a custom firewall rule and reconfigure the agent.
Change the Cloud Tunnel Ports on ESXi Hosts
When you power on the vSphere Replication appliance, it automatically configures all ESXi hosts in your
environment to open TCP ports 10000-10010 for outgoing data transfers.
The vCloud Tunneling Agent in the vSphere Replication appliance uses ports 10000-10010 to receive data
from ESXi instances that host replication sources.
If you do not want to have unused open ports on your ESXi hosts, if the number of open ports is insufficient,
or if you want to change which ports are open, you can reconfigure your firewall settings.
To change the default ports that are used to transfer replication data from ESXi hosts to the vCloud
Tunneling Agent, you must configure each ESXi instance that hosts a replication source virtual machine,
and the vCloud Tunneling Agent.
Procedure
1 Disable the default Replication-to-cloud Traffic rule that is created by the vSphere Replication
appliance.
For detailed procedure, see Allow or Deny Access to an ESXi Service or Management Agent with the
vSphere Web Client.
2 Create a custom firewall rule on each ESXi server that hosts replication source machines.
See Creating custom firewall rules in VMware ESXi 5.0 (KB 2008226).
3 Enable the custom firewall rule that you created on each ESXi host.
See Allow or Deny Access to an ESXi Service or Management Agent with the vSphere Web Client.
What to do next
Configure the vCloud Tunneling Agent to use the ports that you configured on ESXi hosts.
Customize the Ports that vSphere Replication Uses for Tunneling
By default, the vCloud Tunneling Agent in the vSphere Replication appliance is configured to use TCP ports
ranging between 10000 and 10010 to create tunnels to the cloud. All ESXi instances that might host
replication source virtual machines must have their firewall configured to allow outgoing traffic on these
ports.
For each tunnel to cloud, the vCloud Tunneling Agent allocates one unique port from the specified range.
You can reconfigure ESXi hosts and the vCloud Tunneling Agent to reduce the number of open ports or to
change the ports that are used to create tunnels to cloud.
After you reconfigure the ESXi hosts to use custom ports, you must configure the vCloud Tunneling Agent
to use the same custom ports.
Prerequisites
n
Verify that the ports you selected to use for cloud tunnels are open for outgoing traffic on all ESXi
servers that host replication sources.
Chapter 3 Installing and Configuring vSphere Replication to Cloud
VMware, Inc. 13