Firewall Ports KB
VMware has just released a new KB article covering all the firewall ports requirements for the following products:
- Consolidated Backup
- Converter 3.x
- Converter 4.x
- Data Recovery
- ESX 3.x
- ESX 4.x
- ESXi 3.x
- ESXi 4.x
- Guided Consolidation
- Lab Manager
- Orchestrator
- Site Recovery Manager
- Stage Manager
- Update Manager
- vCenter 2.5.x
- vCenter 4.x
- View 3.x
- View 4.x
- View/VDM 2.x
This is something that has been sorely missing from VMware’s official documentation. Some of the PDFs just don’t give the detail you would normally expect. However this KB contains all the headers that a firewall engineer would need. Great stuff.
http://kb.vmware.com/kb/1012382
Of course if you want to get a feel for the overall environment, then Dudley Smith’s fantastic Firewall Ports Diagram is still the best resource out there:
http://www.vreference.com/2009/09/22/firewall-diagram-updated-to-version-3/
4 Responses to Firewall Ports KB
Leave a Reply Cancel reply
Forbes Guthrie
Recent Posts
- Small update to the Reference Card
- Minor update to the vSphere 5 Reference Card
- vSphere 5 vReference Card released
- Cisco UCS boot from iSCSI SAN – ESXi design consideration
- vSphere 5 vReference card – Storage section
- Does 2008 R2 Failover Clustering require a change to the Notify Switches policy?
- vSphere 5 vReference card – Host section
- vSphere 5 vReference card – Install section
- Auto Deploy design concern
- vSphere 5 vReference card – vCenter section
Recent Comments
- honglus on How to PXE boot from your trunked vmnic0
- Sunmeet on Understanding ESXi – stateless, diskless, feckless
- Forbes Guthrie on vSphere 5 Card
- Forbes Guthrie on vSphere 5 Card
- Jakk on vSphere 5 Card
- Purushothama S on vSphere 5 notes
- Bjorn on vSphere 5 Card
- Chris on Minor update to the vSphere 5 Reference Card
- Michael Webster on Auto Deploy design concern
- Ankur Maheshwari on vSphere 5 notes
Twitter
- As much as I've become an NFS supporter over the years, VMFS5 & ATS is really making me like iSCSI & its better multipathing. : 2 weeks ago
- @__wintertale__ Hi Iona (& Lesley). Welcome to the twitterverse from a cloudy and wet Vancouver. How's the coffee? : 3 weeks ago
- RT @jtroyer: ... Kaua'i http://t.co/s4Ovo4jD << Staying in same resort next month. Pls, no destroying it with wild parties ;) : 3 weeks ago
- RT @dobaer: @forbesguthrie How was the run in your shiny new shoes? << Nice, the trails around Vancouver are stunning. : 3 weeks ago
- @h0bbel I'm a Salomon addict, but I'm scared to get these ones muddy :) : 3 weeks ago
- Just took my pwutty new #salomon trail shoes for an hour's run in Pacific Spirit Park. http://t.co/7dAQDXgl : 3 weeks ago
- RT @alim__k: @forbesguthrie @keith_aasen look at you guys, figuring this out over social media ;-) < that's where I do all my best designs : 3 weeks ago
- @keith_aasen Great, just what I was after. And presumably one per controller to prevent performance degradation on failover (after refill) : 3 weeks ago
- @keith_aasen You're the VDI sizing TR author :) You're my Guru! : 3 weeks ago
- NetApp gurus: VDI on 3170 - where's FlashCache watershed for 2x 512GB to 4. When is it 2TB not 1TB? Don't say "it depends" /cc @keith_aasen : 3 weeks ago






I just noticed that it is missing the following for ESX 4 (and maybe 4i):
“5900-5964 RFB protocol, which is used by management tools such as VNC Incoming and outgoing TCP”
See ESX Configuration Guide 4.0U1 Page 152
It would also be nice to show if the ESX ports are from the COS or VMkernel interface.
Agreed, having them listed by COS/vKernel/VMotion/FT/etc would be very helpful since they’d usually be VLAN’d apart.
Well there are also some ports missing for Data Recovery, 902, 443 and 53 which is required by the appliance.. http://www.mingle-mangle.org/2009/08/vmware-data-recovery-and-ports/
Marcus
Hi Marcus,
I know 443 is a requirement, but can you point me to a VMware source which states it needs 902 and 53? Or is this just from personal experience?
Thanks, Forbes.