8.1

Table Of Contents
You can change the default ports that are used to transfer replication data from ESXi hosts to the vCloud
Tunneling Agent. To change the default ports, you must configure each ESXi instance that hosts a
replication source virtual machine, and the vCloud Tunneling Agent.
Procedure
1 Disable the default Replication-to-cloud Traffic rule that the vSphere Replication appliance creates.
For a detailed procedure, see Manage ESXi Firewall Settings.
2 Create a custom firewall rule on each ESXi server that hosts replication source machines.
See Creating custom firewall rules in VMware ESXi 5.0 (KB 2008226).
3 Enable the custom firewall rule that you created on each ESXi host.
See Manage ESXi Firewall Settings.
What to do next
Configure the vCloud Tunneling Agent to use the ports that you configured on ESXi hosts.
Customize the Ports That vSphere Replication Uses for Tunneling
By default, the vCloud Tunneling Agent in the vSphere Replication appliance is configured to use TCP
ports ranging between 10000 and 10010 to create tunnels to the cloud. All ESXi instances that might host
replication source virtual machines must have their firewall configured to allow outgoing traffic on these
ports.
For each tunnel to cloud, the vCloud Tunneling Agent allocates one unique port from the specified range.
You can reconfigure ESXi hosts and the vCloud Tunneling Agent to reduce the number of open ports or to
change the ports that are used to create tunnels to cloud.
After you reconfigure the ESXi hosts to use custom ports, you must configure the vCloud Tunneling Agent
to use the same custom ports.
Prerequisites
n
Verify that the ports you selected to use for cloud tunnels are open for outgoing traffic on all ESXi
servers that host replication sources.
n
Verify that you know the IP address of the vSphere Replication appliance in your environment. To
check the IP address of the vSphere Replication appliance, open the Site Recovery user interface,
select Menu > Replications within the same vCenter Server, and select the vCenter Server. On
the Site tab, click Summary.
n
Verify that you have root user credentials for the vSphere Replication appliance. The IP address of
the vSphere Replication appliance is listed on the Server row.
n
Verify that TCP port 22 is open on the vSphere Replication appliance, and that SSH connections are
enabled. See topic Unable to Establish an SSH Connection to the vSphere Replication Appliance in
the Using vSphere Replication document.
vSphere Replication for Disaster Recovery to Cloud
VMware, Inc. 10