6.7

Table Of Contents
The firewall requirements for standalone hosts are similar to requirements when a vCenter Server is
present.
n
Use a firewall to protect your ESXi layer or, depending on your configuration, your clients, and the
ESXi layer. This firewall provides basic protection for your network.
n
Licensing in this type of configuration is part of the ESXi package that you install on each of the hosts.
Because licensing is resident to ESXi, a separate License Server with a firewall is not required.
You can configure firewall ports using ESXCLI or using the VMware Host Client. See vSphere Single Host
Management - VMware Host Client.
Connecting to the Virtual Machine Console Through a Firewall
Certain ports must be open for user and administrator communication with the virtual machine console.
Which ports must be open depends on the type of virtual machine console, and on whether you connect
through vCenter Server with the vSphere Web Client or directly to the ESXi host from the
VMware Host Client.
Connecting to a Browser-Based Virtual Machine Console Through the
vSphere Web Client
When you are connecting with the vSphere Web Client, you always connect to the vCenter Server system
that manages the ESXi host, and access the virtual machine console from there.
If you are using the vSphere Web Client and connecting to a browser-based virtual machine console, the
following access must be possible:
n
The firewall must allow vSphere Web Client to access vCenter Server on port 9443.
n
The firewall must allow vCenter Server to access the ESXi host on port 902.
Connecting to a Standalone Virtual Machine Console Through the
vSphere Web Client
If you are using the vSphere Web Client and connecting to a standalone virtual machine console, the
following access must be possible:
n
The firewall must allow vSphere Web Client to access vCenter Server on port 9443.
n
The firewall must allow the standalone virtual machine console to access vCenter Server on port
9443 and to access the ESXi host on port 902.
Connecting to ESXi Hosts Directly with the VMware Host Client
You can use the VMware Host Client virtual machine console if you connect directly to an ESXi host.
Note Do not use the VMware Host Client to connect directly to hosts that are managed by a
vCenter Server system. If you make changes to such hosts from the VMware Host Client, instability in
your environment results.
The firewall must allow access to the ESXi host on ports 443 and 902
vSphere Security
VMware, Inc. 196