6.0

Table Of Contents
Manage ESXi Firewall Settings by Using the VMware Host Client
When you are logged in to an ESXi host with the VMware Host Client, you can congure incoming and
outgoing rewall connections for a service or a management agent.
N If dierent services have overlapping port rules, enabling one service might implicitly enable other
services. You can specify which IP addresses are allowed to access each service on the host to avoid this
problem.
Procedure
1 Click Networking in the VMware Host Client inventory.
2 Click Firewall rules.
The VMware Host Client displays a list of active incoming and outgoing connections with the
corresponding rewall ports.
3 For some services you can manage service details. Right-click a service and select an option from the
pop-up menu.
n
Use the Start, Stop, or Restart buons to change the status of a service temporarily.
n
Change the Startup Policy to congure the service to start and stop with the host, the rewall ports,
or manually.
Add Allowed IP Addresses for an ESXi Host by Using the VMware Host Client
By default, the rewall for each service allows access to all IP addresses. To restrict trac, congure each
service to allow trac only from your management subnet. You can also deselect some services if your
environment does not use them.
Procedure
1 Click Networking in the VMware Host Client inventory and click Firewall rules.
2 Click a service from the list and click Edit .
3 In the Allowed IP Addresses section, click Only allow connections from the following networks and
enter the IP addresses of networks that you want to connect to the host.
Separate IP addressees with commas. You can use the following address formats:
n
192.168.0.0/24
n
192.168.1.2, 2001::1/64
n
fd3e:29a6:0a81:e478::/64
4 Click OK.
Chapter 5 Networking in the VMware Host Client
VMware, Inc. 121