6.7

Table Of Contents
Table 52. Recommendations for Enhanced Performance (Continued)
System Element Recommendation
Processors Faster processors improve ESXi performance. For certain
workloads, larger caches improve ESXi performance.
Hardware compatibility Use devices in your server that are supported by ESXi 6.7
drivers. See the Hardware Compatibility Guide at
http://www.vmware.com/resources/compatibility.
Incoming and Outgoing Firewall Ports for ESXi Hosts
The vSphere Web Client and the VMware Host Client allow you to open and close firewall ports for each
service or to allow traffic from selected IP addresses.
The following table lists the firewalls for services that are installed by default. If you install other VIBs on
your host, additional services and firewall ports might become available. The information is primarily for
services that are visible in the vSphere Web Client but the table includes some other ports as well.
Table 53. Incoming Firewall Connections
Port
Protoc
ol Service Description
5988 TCP CIM Server Server for CIM (Common Information Model).
5989 TCP CIM Secure Server Secure server for CIM.
427 TCP,
UDP
CIM SLP The CIM client uses the Service Location Protocol, version 2 (SLPv2) to find
CIM servers.
546 DHCPv6 DHCP client for IPv6.
8301, 8302 UDP DVSSync DVSSync ports are used for synchronizing states of distributed virtual ports
between hosts that have VMware FT record/replay enabled. Only hosts that
run primary or backup virtual machines must have these ports open. On hosts
that are not using VMware FT these ports do not have to be open.
902 TCP NFC Network File Copy (NFC) provides a file-type-aware FTP service for vSphere
components. ESXi uses NFC for operations such as copying and moving data
between datastores by default.
12345, 23451 UDP vSANClustering
Service
VMware vSAN Cluster Monitoring and Membership Directory Service. Uses
UDP-based IP multicast to establish cluster members and distribute vSAN
metadata to all cluster members. If disabled, vSAN does not work.
68 UDP DHCP Client DHCP client for IPv4.
53 UDP DNS Client DNS client.
8200, 8100,
8300
TCP,
UDP
Fault Tolerance Traffic between hosts for vSphere Fault Tolerance (FT).
6999 UDP NSX Distributed
Logical Router
Service
NSX Virtual Distributed Router service. The firewall port associated with this
service is opened when NSX VIBs are installed and the VDR module is
created. If no VDR instances are associated with the host, the port does not
have to be open.
This service was called NSX Distributed Logical Router in earlier versions of
the product.
VMware ESXi Installation and Setup
VMware, Inc. 14