6.5.1

Table Of Contents
Connecting to ESXi Hosts Directly with the VMware Host Client
You can use the VMware Host Client virtual machine console if you connect directly to an ESXi host.
Note Do not use the VMware Host Client to connect directly to hosts that are managed by a
vCenter Server system. If you make changes to such hosts from the VMware Host Client, instability in
your environment results.
The firewall must allow access to the ESXi host on ports 443 and 902
The VMware Host Client uses port 902 to provide a connection for guest operating system MKS activities
on virtual machines. It is through this port that users interact with the guest operating systems and
applications of the virtual machine. VMware does not support configuring a different port for this function.
Secure the Physical Switch
Secure the physical switch on each ESXi host to prevent attackers from gaining access to the host and its
virtual machines.
For best protection of your hosts, ensure that physical switch ports are configured with spanning tree
disabled and ensure that the non-negotiate option is configured for trunk links between external physical
switches and virtual switches in Virtual Switch Tagging (VST) mode.
Procedure
1 Log in to the physical switch and ensure that spanning tree protocol is disabled or that Port Fast is
configured for all physical switch ports that are connected to ESXi hosts.
2 For virtual machines that perform bridging or routing, check periodically that the first upstream
physical switch port is configured with BPDU Guard and Port Fast disabled and with spanning tree
protocol enabled.
In vSphere 5.1 and later, to prevent the physical switch from potential Denial of Service (DoS)
attacks, you can turn on the guest BPDU filter on the ESXi hosts.
3 Log in to the physical switch and ensure that Dynamic Trunking Protocol (DTP) is not enabled on the
physical switch ports that are connected to the ESXi hosts.
4 Routinely check physical switch ports to ensure that they are properly configured as trunk ports if
connected to virtual switch VLAN trunking ports.
vSphere Security
VMware, Inc. 180