6.7

Table Of Contents
4 In the Firewall section, click Edit.
The display shows firewall rule sets, which include the name of the rule and the associated
information.
5 Select the rule sets to enable, or deselect the rule sets to disable.
Column Description
Incoming Ports and Outgoing Ports The ports that the vSphere Web Client opens for the service
Protocol Protocol that a service uses.
Daemon Status of daemons associated with the service
6 For some services, you can manage service details.
n
Use the Start, Stop, or Restart buttons to change the status of a service temporarily.
n
Change the Startup Policy to have the service start with the host or with port usage.
7 For some services, you can explicitly specify IP addresses from which connections are allowed.
See Add Allowed IP Addresses for an ESXi Host.
8 Click OK.
Add Allowed IP Addresses for an ESXi Host
By default, the firewall for each service allows access to all IP addresses. To restrict traffic, change each
service to allow traffic only from your management subnet. You might also deselect some services if your
environment does not use them.
You can use the vSphere Web Client, vCLI, or PowerCLI to update the Allowed IP list for a service. By
default, all IP addresses are allowed for a service.
Adding Allowed IP Addresses to the ESXi Firewall
(http://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_adding_allowed_IP_to_esxi_firewall)
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click Configure.
3 Under System, click Security Profile.
4 In the Firewall section, click Edit and select a service from the list.
5 In the Allowed IP Addresses section, deselect Allow connections from any IP address and enter
the IP addresses of networks that are allowed to connect to the host.
Separate IP addresses with commas. You can use the following address formats:
n
192.168.0.0/24
n
192.168.1.2, 2001::1/64
vSphere Security
VMware, Inc. 69