6.5.1

Table Of Contents
You might also include firewalls at other access points in the network, depending on network usage and
on the level of security that clients require. Select the locations for your firewalls based on the security
risks for your network configuration. The following firewall locations are commonly used.
n
Between the vSphere Web Client or a third-party network-management client and vCenter Server.
n
If your users access virtual machines through a Web browser, between the Web browser and the
ESXi host.
n
If your users access virtual machines through the vSphere Web Client, between the
vSphere Web Client and the ESXi host. This connection is in addition to the connection between the
vSphere Web Client and vCenter Server, and it requires a different port.
n
Between vCenter Server and the ESXi hosts.
n
Between the ESXi hosts in your network. Although traffic between hosts is usually considered trusted,
you can add firewalls between them if you are concerned about security breaches from machine to
machine.
If you add firewalls between ESXi hosts and plan to migrate virtual machines between them, open
ports in any firewall that divides the source host from the target hosts.
n
Between the ESXi hosts and network storage such as NFS or iSCSI storage. These ports are not
specific to VMware. Configure them according to the specifications for your network.
Connecting to vCenter Server Through a Firewall
Open TCP port 443 in the firewall to enable vCenter Server to receive data. By default vCenter Server
uses TCP port 443 to listen for data from its clients. If you have a firewall between vCenter Server and its
clients, you must configure a connection through which vCenter Server can receive data from the clients.
Firewall configuration depends on what is used at your site, ask your local firewall system administrator
for information. How you open ports depends on whether you use a vCenter Server Appliance or a
vCenter Server Windows installation.
Connecting ESXi Hosts Through Firewalls
If you have a firewall between you ESXi hosts and vCenter Server, ensure that the managed hosts can
receive data.
To configure a connection for receiving data, open ports for traffic from services such as vSphere High
Availability, vMotion, and vSphere Fault Tolerance. See ESXi Firewall Configuration for a discussion of
configuration files, vSphere Web Client access, and firewall commands. See Incoming and Outgoing
Firewall Ports for ESXi Hosts for a list of ports.
Firewalls for Configurations Without vCenter Server
If your environment does not include vCenter Server, clients can connect directly to the ESXi network.
You can connect to a standalone ESXi host in several ways.
n
VMware Host Client
vSphere Security
VMware, Inc. 178