6.5.1

Table Of Contents
Cause
Active Directory requires the activeDirectoryAll firewall rule set. You must enable the rule set in the
firewall configuration. If you omit this setting, the system adds the necessary firewall rules when the host
joins the domain, but the host will be noncompliant because of the mismatch in firewall rules. The host will
also be noncompliant if you remove it from the domain without disabling the Active Directory rule set.
Solution
1 Browse to the host profile in the vSphere Web Client.
To find a host profile, click Policies and Profiles > Host Profiles on the vSphere Web Client Home
page.
2 Right-click the host profile and select Edit Settings.
3 Click Next.
4 Select Security and Services > Firewall Configuration > Firewall configuration > Ruleset
Configuration.
5 Ensure that activeDirectoryAll is selected.
6 In the right panel, select the Flag indicating whether ruleset should be enabled check box.
Deselect the check box if the host is leaving the domain.
7 Click Next, and then click Finish to complete the change to the host profile.
Unable to Download VIBs When Using vCenter Server
Reverse Proxy
You are unable to download VIBs if vCenter Server is using a custom port for the reverse proxy.
Problem
If you configure vCenter Server reverse proxy to use a custom port, the VIB downloads fail.
Cause
If vCenter Server is using a custom port for the reverse proxy, the custom port is not automatically
enabled in the ESXi firewall and the VIB downloads fail.
Solution
1 Open an SSH connection to the host and log in as root.
2 (Optional) List the existing firewall rules.
esxcli network firewall ruleset list
3 (Optional) Back up the /etc/vmware/firewall/service.xml file.
cp /etc/vmware/firewall/service.xml /etc/vmware/firewall/service.xml.bak
vSphere Troubleshooting
VMware, Inc. 35