Sunday, August 10, 2014

Vmware ports

Note: Ports used with the Virtual Infrastructure / vSphere Client are listed in a separate table at the end of this article.

ProductPortProtocolSourceTargetPurpose
AppSpeed80TCPAppSpeed ServervCenter Server 4vCenter proxy interface. Used only during setup to verify the proxy is setup correctly. Port 80 is the default Web Service Port, but a different TCP port can be configured in vCenter Server 4.
AppSpeed443TCPAppSpeed ServervCenter Server 4Default port for communications. A different TCP port can be configured in vCenter Server 4.
AppSpeed22TCPAppSpeed ServerAppSpeed ProbeConnections to the probes to access the probes outside of the VPN.
AppSpeed123TCPAppSpeed ServerAppSpeed ProbeNTP services
AppSpeed1194TCP/UDPAppSpeed ServerAppSpeed ProbeCommunications over OpenVPN
Auto Deploy Server#6501TCPESXivCenter ServerAuto Deploy service
Auto Deploy Server6502TCPESXivCenter ServerAuto Deploy management
Consolidated Backup#443TCPVCB Proxy ServervCenter ServerRequired for VCB and vcbMounter communication and backup processes
Consolidated Backup443TCPVCB Proxy ServerESXi/ESX HostRequired for VCB and vcbMounter communication and backup processes
Converter 3.x#137UDPvCenter Converter ServerSource Computer to be convertedFor hot migration. Not required if the source computer does not use NetBIOS
Converter 3.x138UDPvCenter Converter ServerSource Computer to be convertedFor hot migration. Not required if the source computer does not use NetBIOS
Converter 3.x139TCPvCenter Converter ServerSource Computer to be convertedFor hot migration. Not required if the source computer does not use NetBIOS
Converter 3.x443TCPSource Computer to be convertedESXi/ESX HostRequired for destination VM access when target is ESXi/ESX/vCenter
Converter 3.x443TCPSource Computer to be convertedvCenter ServerRequired if vCenter Server is the conversion target
Converter 3.x443TCPvCenter Converter ServervCenter ServerRequired if vCenter Server is the conversion target
Converter 3.x443TCPvCenter Converter ServerESXi/ESX HostRequired for system conversion
Converter 3.x445TCPvCenter Converter ServerSource Computer to be convertedRequired for system conversion. Not required if the source computer uses NetBIOS
Converter 3.x902TCPSource Computer to be convertedESXi/ESX HostRequired for data transport during cloning of system to be converted to target ESXi/ESX Host
Converter 4.x#22TCPHelper Virtual MachineSource Computer to be convertedRequired for conversion of Linux-based source computers (data flows from source to VM)
Converter 4.x22TCPvCenter Converter ServerSource Computer to be convertedRequired for conversion of Linux-based source computers
Converter 4.x137UDPvCenter Converter ServerSource Computer to be convertedFor hot migration. Not required if the source computer does not use NetBIOS
Converter 4.x138UDPvCenter Converter ServerSource Computer to be convertedFor hot migration. Not required if the source computer does not use NetBIOS
Converter 4.x139TCPvCenter Converter ServerSource Computer to be convertedFor hot migration. Not required if the source computer does not use NetBIOS
Converter 4.x443TCPvCenter Converter ClientvCenter Converter ServerOnly required if the Converter Client and Converter Server were installed on different systems
Converter 4.x443TCPSource Computer to be convertedESXi/ESX HostRequired for destination VM access when target is ESXi/ESX/vCenter
Converter 4.x443TCPSource Computer to be convertedvCenter ServerRequired if vCenter Server is the conversion target
Converter 4.x443TCPvCenter Converter ServervCenter ServerRequired if vCenter Server is the conversion target
Converter 4.x443TCPvCenter Converter ServerESXi/ESX HostRequired for system conversion
Converter 4.x443TCPvCenter Converter ServerHelper Virtual MachineRequired for conversion of Linux-based source computers
Converter 4.x445TCPvCenter Converter ServerSource Computer to be convertedRequired for system conversion. Not required if the source computer uses NetBIOS
Converter 4.x902TCPSource Computer to be convertedESXi/ESX HostRequired for data transport during cloning of system to be converted to target ESXi/ESX Host
Converter 4.x9089, 9090TCPvCenter Converter ServerSource Computer to be convertedRequired for system conversion. Remote agent deployment
Converter 5.x#22TCPConverter Standalone serverpowered-on source machineUsed to establish an SSH connection between the Converter Standalone server and the source Linux machine
Converter 5.x137UDPConverter Standalone serverpowered-on source machineFor hot migration. Not required if the source computer does not use NetBIOS
Converter 5.x138UDPConverter Standalone serverpowered-on source machineFor hot migration. Not required if the source computer does not use NetBIOS
Converter 5.x139TCPConverter Standalone serverpowered-on source machineFor hot migration. Not required if the source computer does not use NetBIOS
Converter 5.x443TCPConverter Standalone servervCenter ServerRequired only if theconversion destination is a vCenter Server
Converter 5.x443TCPConverter Standalone clientConverter Standalone serverRequired only if the Converter Standalone server and Linux client components are on different machines
Converter 5.x443TCPConverter Standalone clientvCenter serverRequired only if the Converter Standalone server and client components are on different machines
Converter 5.x22TCPPowered-on Source Linux machineESXi/ESX HostUses secure connection port 22 to Host
Converter 5.x443, 902TCPPowered-on Source Windows machineESXi/ESX HostRequired for data transfer to destination ESXi/ESX host
Converter 5.x445TCPConverter Standalone serverpowered-on source machineRequired for system conversion. Not required if the source computer uses NetBIOS
Converter 5.x9089TCPConverter Standalone serverpowered-on source machineRequired for system conversion. Remote agent deployment
Data Recovery#443TCPData Recovery AppliancevCenter ServerVDR to vCenter Server communications
Data Recovery902TCPData Recovery ApplianceESX HostVDR to ESX communications
Data Recovery22024TCPData Recovery vSphere Client Plug-inData Recovery ApplianceData Recovery management
ESX 3.x21TCPFTP ClientESX HostFTP
ESX 3.x21TCPESX HostFTP ServerFTP
ESX 3.x22TCPSSH ClientESX HostSSH
ESX 3.x22TCPESX HostSSH ServerSSH
ESX 3.x53UDPESXi/ESX HostDNS ServerDNS
ESX 3.x80TCPClient PCESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESX 3.x88TCPESX HostActive Directory ServerPAM Active Directory Authentication - Kerberos
ESX 3.x111UDPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESX 3.x111TCPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESX 3.x123UDPESXi/ESX HostNTP Time ServerNTP Client
ESX 3.x137 to 139TCPESX HostSMB ServerSMB
ESX 3.x161UDPSNMP ServerESX HostSNMP Polling
ESX 3.x162UDPESX HostSNMP CollectorSNMP Trap Send
ESX 3.x389TCP/UDPESX HostLDAP ServerPAM Active Directory Authentication – LDAP
ESX 3.x427UDPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESX 3.x427TCPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESX 3.x443TCPClient PCESX HostHost VI Management via web browser
ESX 3.x443TCPVI / vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX Host management connection
ESX 3.x443TCPESXi/ESX HostESXi/ESX HostHost to host VM migration and provisioning
ESX 3.x445TCPESX HostSMB ServerSMB
ESX 3.x445TCPESX HostMS Directory Services ServerPAM Active Directory Authentication
ESX 3.x445UDPESX HostMS Directory Services ServerPAM Active Directory Authentication
ESX 3.x464TCPESX HostActive Directory ServerPAM Active Directory Authentication – Kerberos Password Services
ESX 3.x514UDPESXi/ESX HostSyslog ServerRemote syslog logging
ESX 3.x902TCPVI /vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX hosted VM connectivity (MKS)
ESX 3.x902TCP/UDPESXi/ESX HostESXi/ESX HostAuthentication, Provisioning, VM Migration
ESX 3.x902TCP/UDPESXi/ESX HostVirtual Center 3.x/ vCenter Server 4.xHeartbeat
ESX 3.x903TCPVI / vSphere ClientESXi/ESX HostVM Remote Console
ESX 3.x2049UDPESXi/ESX HostNFS ServerNFS Client
ESX 3.x2049TCPESXi/ESX HostNFS ServerNFS Client
ESX 3.x2050 to 2250UDPESXi/ESX HostESXi/ESX HostVMware HA
ESX 3.x3260TCPESXi/ESX HostiSCSI SANSoftware iSCSI Client and Hardware iSCSI HBA
ESX 3.x5988TCPESXi/ESX HostESXi/ESX HostCIM Client to CIM Secure Server
ESX 3.x5989TCPESXi/ESX HostVirtualCenter/vCenter ServerCIM Secure Server to CIM Client
ESX 3.x5989TCPVirtualCenter/vCenter ServerESXi/ESX HostCIM Client to CIM Secure Server
ESX 3.x8000TCPESXi/ESX Host (VM Target)ESXi/ESX Host (VM Source)VMotion Communication on VMKernel Interface
ESX 3.x8000TCPESXi/ESX Host (VM Source)ESXi/ESX Host (VM Target)VMotion Communication on VMKernel Interface
ESX 3.x8042 to 8045TCPESXi/ESX HostESXi/ESX HostVMware HA
ESX 3.x27000TCPESXi/ESX HostVMware License ServerESXi/ESX 3.x Host to License Server communication
ESX 3.x27010TCPESXi/ESX HostVMware License ServerESXi/ESX 3.x Host to License Server communication
ESX 4.x#21TCPFTP ClientESX HostFTP
ESX 4.x21TCPESX HostFTP ServerFTP
ESX 4.x22TCPESX HostSSH ServerSSH
ESX 4.x22TCPSSH ClientESX HostSSH
ESX 4.x53UDPESXi/ESX HostDNS ServerDNS
ESX 4.x80TCPClient PCESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESX 4.x88TCPESX HostActive Directory ServerPAM Active Directory Authentication - Kerberos
ESX 4.x111UDPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESX 4.x111TCPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESX 4.x123UDPESXi/ESX HostNTP Time ServerNTP Client
ESX 4.x137 to 139TCPESX HostSMB ServerSMB
ESX 4.x161UDPSNMP ServerESX HostSNMP Polling
ESX 4.x162UDPESX HostSNMP CollectorSNMP Trap Send
ESX 4.x389TCP/UDPESX HostLDAP ServerPAM Active Directory Authentication – LDAP
ESX 4.x427UDPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESX 4.x427TCPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESX 4.x443TCPESXi/ESX HostESXi/ESX HostHost to Host VM migration and provisioning
ESX 4.x443TCPClient PCESX HostHost VI Management via web browser
ESX 4.x443TCPvSphere ClientESXi/ESX HostvSphere Client to ESXi/ESX Host management connection
ESX 4.x445UDPESX HostMS Directory Services ServerPAM Active Directory Authentication
ESX 4.x445TCPESX HostMS Directory Services ServerPAM Active Directory Authentication
ESX 4.x445TCPESX HostSMB ServerSMB
ESX 4.x464TCPESX HostActive Directory ServerPAM Active Directory Authentication – Kerberos Password Services
ESX 4.x514UDPESXi/ESX HostSyslog ServerRemote syslog logging
ESX 4.x902TCPvSphere ClientESXi/ESX HostvSphere Client to ESXi/ESX hosted VM connectivity (MKS)
ESX 4.x902TCP/UDPESXi/ESX HostESXi/ESX HostAuthentication, Provisioning, VM Migration
ESX 4.x902TCP/UDPESXi/ESX HostvCenter Server 4.xHeartbeat
ESX 4.x903TCPVI / vSphere ClientESXi/ESX HostVM Remote Console (MKS)
ESX 4.x1024 (dynamic)TCP/UDPESX HostActive Directory ServerBi-directional communication on TCP/UDP ports is required between the ESX host and the Active Directory Domain Controller (via the netlogond process on the ESX host). SeeActive Directory and Active Directory Domain Services Port Requirements and MS article179442.
ESX 4.x2049UDPESXi/ESX HostNFS ServerNFS Client
ESX 4.x2049TCPESXi/ESX HostNFS ServerNFS Client
ESX 4.x2050 to 2250UDPESXi/ESX HostESXi/ESX HostVMware HA
ESX 4.x3260TCPESXi/ESX HostiSCSI SANSoftware iSCSI Client and Hardware iSCSI HBA
ESX 4.x5900 to 5964TCPESXi/ESX HostESXi/ESX HostRFB Protocol used by management toolssuch as VNC
ESX 4.x5988TCPESXi/ESX HostESXi/ESX HostCIM Client to CIM Secure Server
ESX 4.x5989TCPVirtualCenter/vCenterESXi/ESX HostCIM Client to CIM Secure Server
ESX 4.x5989TCPESXi/ESX HostVirtualCenter/vCenterCIM Secure Server to CIM Client
ESX 4.x8000TCPESXi/ESX Host (VM Target)ESXi/ESX Host (VM Source)VMotion Communication on VMKernel Interface
ESX 4.x8000TCPESXi/ESX Host (VM Source)ESXi/ESX Host (VM Target)VMotion Communication on VMKernel Interface
ESX 4.x8042 to 8045TCPESXi/ESX HostESXi/ESX HostVMware HA
ESX 4.x47UDPESXi/ESX HostPhysical SwitchesvDS (Virtual Distributed Switch) Broadcast
ESX 4.x8100TCP/UDPESXi/ESX 4 HostESXi/ESX 4.x HostVMware Fault Tolerance. ESXi/ESX 4 only.
ESX 4.x8200TCP/UDPESXi/ESX 4 HostESXi/ESX 4.x HostVMware Fault Tolerance. ESXi/ESX 4 only.
ESX 4.x8301UDPESXi/ESX 4.x HostESXi/ESX 4.xDVS Port Information
ESX 4.x8302UDPESXi/ESX 4.x HostESXi/ESX 4.x HostDVS Port Information
ESXi 3.x#53UDPESXi/ESX HostDNS ServerDNS
ESXi 3.x80TCPClient PCESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESXi 3.x111TCPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESXi 3.x111UDPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESXi 3.x123UDPESXi/ESX HostNTP Time ServerNTP Client
ESXi 3.x162UDPESX HostSNMP CollectorSNMP Trap Send
ESXi 3.x427UDPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESXi 3.x427TCPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESXi 3.x443TCPVI / vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX Host management connection
ESXi 3.x443TCPESXi/ESX HostESXi/ESX HostHost to host VM migration and provisioning
ESXi 3.x514UDPESXi/ESX HostSyslog ServerRemote syslog logging
ESXi 3.x902TCPVI / vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX hosted VM connectivity (MKS/Remote Console)
ESXi 3.x902TCP/UDPESXi/ESX HostESXi/ESX HostAuthentication, Provisioning, VM Migration
ESXi 3.x902TCP/UDPESXi/ESX HostVirtual Center 3.x/ vCenter Server 4.xHeartbeat
ESXi 3.x903TCPVI / vSphere ClientESXi/ESX HostVM Remote VM Console (MKS)
ESXi 3.x2049TCPESXi/ESX HostNFS ServerNFS Client
ESXi 3.x2049UDPESXi/ESX HostNFS ServerNFS Client
ESXi 3.x2050 to 2250UDPESXi/ESX HostESXi/ESX HostVMware HA
ESXi 3.x3260TCPESXi/ESX HostiSCSI SANSoftware iSCSI Client and Hardware iSCSI HBA
ESXi 3.x5988TCPESXi/ESX HostESXi/ESX HostCIM Client to CIM Secure Server
ESXi 3.x5989TCPVirtualCenter/vCenterESXi/ESX HostCIM Client to CIM Secure Server
ESXi 3.x5989TCPESXi/ESX HostVirtualCenter/vCenterCIM Secure Server to CIM Client
ESXi 3.x8000TCPESXi/ESX Host (VM Target)ESXi/ESX Host (VM Source)VMotion Communication on VMKernel Interface
ESXi 3.x8000TCPESXi/ESX Host (VM Source)ESXi/ESX Host (VM Target)VMotion Communication on VMKernel Interface
ESXi 3.x8042 to 8045TCPESXi/ESX HostESXi/ESX HostVMware HA
ESXi 3.x27000TCPESXi/ESX HostVMware License ServerESXi/ESX 3.x Host to License Server communication
ESXi 3.x27010TCPESXi/ESX HostVMware License ServerESXi/ESX 3.x Host to License Server communication
ESXi 4.x#53UDPESXi/ESX HostDNS ServerDNS
ESXi 4.x80TCPClient PCESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESXi 4.x88TCPESXi hostActive Directory ServerPAM Active Directory Authentication - Kerberos
ESXi 4.x111TCPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESXi 4.x111UDPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESXi 4.x123UDPESXi/ESX HostNTP Time ServerNTP Client
ESXi 4.x161UDPSNMP ServerESXi 4.x HostSNMP Polling. Not used in ESXi 3.x
ESXi 4.x162UDPESXi HostSNMP CollectorSNMP Trap Send
ESXi 4.x389TCP/UDPESXi hostLDAP ServerPAM Active Directory Authentication - Kerberos
ESXi 4.x427UDPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESXi 4.x427TCPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESXi 4.x443TCPVI / vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX Host management connection
ESXi 4.x443TCPESXi/ESX HostESXi/ESX HostHost to host VM migration and provisioning
ESXi 4.x445UDPESXi hostMS Directory Services ServerPAM Active Directory Authentication
ESXi 4.x445TCPESXi hostMS Directory Services ServerPAM Active Directory Authentication
ESXi 4.x445TCPESXi hostSMB ServerSMB Server
ESXi 4.x464TCPESXi hostActive Directory ServerPAM Active Directory Authentication - Kerberos
ESXi 4.x514UDPESXi/ESX HostSyslog ServerRemote syslog logging
ESXi 4.x902TCPVI / vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX hosted VM connectivity (MKS/Remote Console)
ESXi 4.x902TCP/UDPESXi/ESX HostESXi/ESX HostAuthentication, Provisioning, VM Migration
ESXi 4.x902TCP/UDPESXi/ESX HostvCenter 4 ServerHeartbeat
ESXi 4.x902TCPVI / vSphere ClientESXi/ESX HostVM Remote VM Console (MKS)
ESXi 4.x1024 (dynamic)TCP/UDPESXi HostActive Directory ServerBi-directional communication on TCP/UDP ports is required between the ESXi host and the Active Directory Domain Controller (via the netlogond process on the ESXi host). SeeActive Directory and Active Directory Domain Services Port Requirements and MS article179442.
ESXi 4.x2049TCPESXi/ESX HostNFS ServerNFS Client
ESXi 4.x2049UDPESXi/ESX HostNFS ServerNFS Client
ESXi 4.x2050 to 2250UDPESXi/ESX HostESXi/ESX HostVMware HA
ESXi 4.x3260TCPESXi/ESX HostiSCSI SANSoftware iSCSI Client and Hardware iSCSI HBA
ESXi 4.x5900to 5964TCPESXi/ESX HostESXi/ESX HostRFB Protocol used by management toolssuch as VNC
ESXi 4.x5988TCPESXi/ESX HostESXi/ESX HostCIM Client to CIM Secure Server
ESXi 4.x5989TCPVirtualCenter/vCenterESXi/ESX HostCIM Client to CIM Secure Server
ESXi 4.x5989TCPESXi/ESX HostVirtualCenter/vCenterCIM Secure Server to CIM Client
ESXi 4.x8000TCPESXi/ESX Host (VM Target)ESXi/ESX Host (VM Source)VMotion Communication on VMkernel Interface
ESXi 4.x8000TCPESXi/ESX Host (VM Source)ESXi/ESX Host (VM Target)VMotion Communication on VMkernel Interface
ESXi 4.x47UDPESXi/ESX HostPhysical SwitchesvDS (Virtual Distributed Switch) Broadcast
ESXi 4.x8042 to 8045TCPESXi/ESX HostESXi/ESX HostVMware HA
ESXi 4.x8100TCP/UDPESXi/ESX 4 HostESXi/ESX 4.x HostVMware Fault Tolerance. ESXi/ESX 4 only.
ESXi 4.x8200TCP/UDPESXi/ESX 4 HostESXi/ESX 4.x HostVMware Fault Tolerance. ESXi/ESX 4 only.
ESXi 4.x8301UDPESXi/ESX 4.x HostESXi/ESX 4.x HostDVS Port Information
ESXi 4.x8302UDPESXi/ESX 4.x HostESXi/ESX 4.x HostDVS Port Information
ESXi 5.x#22TCPClient PCESXi 5.xSSH Server
ESXi 5.x53UDPESXi 5.xDNS ServerDNS Client
ESXi 5.x68UDPESXi 5.xDHCP ServerDHCP Client
ESXi 5.x80TCPClient PCESXi 5.xRedirect Web Browser to HTTPS Service (443)
ESXi 5.x88TCPESXi hostActive Directory ServerPAM Active Directory Authentication - Kerberos
ESXi 5.x111TCPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESXi 5.x111UDPESXi/ESX HostNFS ServerNFS Client – RPC Portmapper
ESXi 5.x123UDPESXi/ESX HostNTP Time ServerNTP Client
ESXi 5.x161UDPSNMP ServerESXi 4.x HostSNMP Polling. Not used in ESXi 3.x
ESXi 5.x162UDPESXi HostSNMP CollectorSNMP Trap Send
ESXi 5.x389TCP/UDPESXi hostLDAP ServerPAM Active Directory Authentication - Kerberos
ESXi 5.x427UDPVI / vSphere ClientESXi/ESX HostCIM Service Location Protocol (SLP)
ESXi 5.x443TCPVI / vSphere ClientESXi/ESX HostVI / vSphere Client to ESXi/ESX Host management connection
ESXi 5.x443TCPESXi/ESX HostESXi/ESX HostHost to host VM migration and provisioning
ESXi 5.x445UDPESXi hostMS Directory Services ServerPAM Active Directory Authentication
ESXi 5.x445TCPESXi hostMS Directory Services ServerPAM Active Directory Authentication
ESXi 5.x445TCPESXi hostSMB ServerSMB Server
ESXi 5.x464TCPESXi hostSee .Active Directory ServerPAM Active Directory Authentication - Kerberos
ESXi 5.x514UDP/TCPESXi 5.xSyslog ServerRemote syslog logging
ESXi 5.x902TCP/UDPESXi 5.xESXi 5.xHost access to other hosts for migration and provisioning
ESXi 5.x902TCPvSphere ClientESXi 5.xvSphere Client access to virtual machine consoles (MKS)
ESXi 5.x902TCP/UDPESXi 5.xvCenter Server(UDP) Status update (heartbeat) connection from E SXi to vCenter Server
ESXi 5.x1024 (dynamic)TCP/UDPESXi HostActive Directory ServerBi-directional communication on TCP/UDP ports is required between the ESXi host and the Active Directory Domain Controller (via the netlogond process on the ESXi host). SeeActive Directory and Active Directory Domain Services Port Requirements and MS article179442.
ESXi 5.x2049TCPESXi 5.xNFS ServerTransactions from NFS storage devices
ESXi 5.x2049UDPESXi 5.xNFS ServerTransactions from NFS storage devices
ESXi 5.x3260TCPESXi 5.xiSCSI storage serverTransactions to iSCSI storage devices
ESXi 5.x5900 to 5964TCPESXi 5.xESXi 5.xRFB protocol, which is used by management tools such as VNC
ESXi 5.x5988TCPCIM ServerESXi 5.xCIM transactions over HTTP
ESXi 5.x5989TCPvCenter ServerESXi 5.xCIM XML transactions over HTTPS
ESXi 5.x5989TCPESXi 5.xvCenter ServerCIM XML transactions over HTTPS
ESXi 5.x8000TCPESXi 5.x (VM Target)ESXi 5.x (VM Source)Requests from vMotion
ESXi 5.x8000TCPESXi 5.x (VM Source)ESXi 5.x (VM Target)Requests from vMotion
ESXi 5.x8100TCP/UDPESXi 5.xESXi 5.xTraffic between hosts for vSphere Fault Tolerance (FT)
ESXi 5.x8182TCP/UDPESXi 5.xESXi 5.xTraffic between hosts for vSphere High Availability (vSphere HA)
ESXi 5.x8200TCP/UDPESXi 5.xESXi 5.xTraffic between hosts for vSphere Fault Tolerance (FT)
ESXi 5.x8301UDPESXi 5.xESXi 5.xDVS Port Information
ESXi 5.x8302UDPESXi 5.xESXi 5.xDVS Port Information
ESXi 5.x31100TCPvCenterSPS ServerInternal Communication Port
ESXi 5.x31000TCPSPS ServervCenterInternal Communication Port
ESXi Dump Collector#6500UDPESXivCenter ServerNetwork coredump server
ESXi Dump Collector8000TCPESXivCenter ServerNetwork coredump web port
ESXi Syslog Collector#8001TCPESXivCenter ServerNetwork syslog server
GuidedConsolidation135TCP/UDPConsolidation Target (Physical Server)vCenter Converter ServerMicrosoft DCE Locator Service, also known at End-Point Mapper
Guided Consolidation137TCP/UDPConsolidation Target (Physical Server)vCenter Converter ServerNetBIOS names service. Firewall administrators frequently see larger numbers of incoming packets to port 137. This is because of Windows servers that use NetBIOS (as well as DNS) to resolve IP addresses to names using the gethostbyaddr() function. As users behind the firewalls visit Windows-based Web sites, those servers frequently respond with NetBIOS lookups.
Guided Consolidation138TCP/UDPConsolidation Target (Physical Server)vCenter Converter ServerNetBIOS datagram Used by Windows, as well as UNIX services (such as SAMBA). Port 138 is used primarily by the SMB browser service that obtains Network Neighborhood information.
Guided Consolidation139TCP/UDPConsolidation Target (Physical Server)vCenter Converter ServerNetBIOS Session Windows File and Printer sharing.
Guided Consolidation445TCP/UDPConsolidation Target (Physical Server)vCenter Converter ServerDNS Direct Hosting port. In Windows 2000 and Windows XP, redirector and server components now support direct hosting for communicating with other computers running Windows 2000 or Windows XP. Direct hosting does not use NetBIOS for name resolution. DNS is used for name resolution, and the Microsoft networking communication is sent directly over TCP without a NetBIOS header. Direct hosting over TCP/IP uses TCP and UDP port 445 instead of the NetBIOS session TCP port 139.
Heartbeat#52267TCPvCenter Server Heartbeat ConsolevCenter Server Heartbeat ServerClient Connection Port
Heartbeat57348TCPvCenter Server Primary ServervCenter Server Secondary ServerDefault Channel Port to communicate between Primary and Secondary server
Lab Manager#137UDPESXi/ESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x
Lab Manager138UDPESXi/ESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x
Lab Manager139TCPESXi/ESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x
Lab Manager389TCP/UDPLab Manager ServerLDAP ServerLDAP Authentication (optional)
Lab Manager443TCPClient PCLab Manager ServerLab Manager Console (Web Browser)
Lab Manager443TCPLab Manager ServervCenter ServerLab Manager to vCenter Server Communication
Lab Manager445TCPESXi/ESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x
Lab Manager514TCPLab Manager ServerVirtual RouterUpdate IP tables and routing on the vRouter
Lab Manager636TCPLab Manager ServerLDAP ServerLDAPS Authentication (optional)
Lab Manager1433TCPLab Manager ServerMicrosoft SQL ServerLab Manager Connectivity to Microsoft SQL Server (for LM database)
Lab Manager5212TCPLab Manager ServerESXi/ESX HostLab Manager Agent. ESXi requires Lab Manager 4.x
Orchestrator#25TCPVCO ServerSMTP ServerEmail notifications
Orchestrator389TCP/UDPVCO ServerLDAP ServerLDAP Authentication
Orchestrator443TCPVCO ServervCenter ServerUsed to obtain virtual infrastructure and virtual machine information from orchestrated vCenter Server(s) through the vCenter API
Orchestrator636TCPVCO ServerLDAP ServerVCO uses LDAP authentication and group membership to determine role authorization in LCM and access to VMs/requests. This is the SSL secured LDAP protocol LDAPS (the SSL pendent of 389). This is used for secured LDAP authentication
Orchestrator1433TCPVCO ServerMicrosoft SQL ServervCenter Orchestrator Server to Microsoft SQL Server for VCO Database
Orchestrator1521TCPVCO ServerOracle Database ServervCenter Orchestrator Server to Oracle for VCO Database
Orchestrator3306TCPVCO ServerMySQL ServervCenter Orchestrator Server to MySQL Server for VCO Database
Orchestrator5432TCPVCO ServerPostgresSQL ServervCenter Orchestrator Server to PostgresSQL Server for VCO Database
Orchestrator8230TCPVCO ClientVCO ServerLookup port – The main port to communicate with Orchestrator Configurator server (JNDI port). All other ports communicate with the Orchestrator Configurator smart client through this one. It is part of the JBoss Application server infrastructure
Orchestrator8240TCPVCO ClientVCO ServerCommand port – The application communication port (RMI container port), it is used for remote invocations. It is part of the JBoss Application server infrastructure.
Orchestrator8244TCPVCO ClientVCO ServerData port used to access all Orchestrator data models, such as workflows and policies. It is part of the JBoss application server infrastructure.
Orchestrator8250TCPVCO ClientVCO ServerMessaging port – The Java messaging port used to dispatch events. It is part of the JBoss Application server infrastructure
Orchestrator8280TCPVCO ServerVCO ServerPort used by VCO Server to connect to the Web front-end via HTTP
Orchestrator8281TCPVCO ServerVCO ServerPort used by VCO Server to connect to the Web front-end via HTTPS
Orchestrator8281TCPvCenter ServerVCO ServerPort used by VCO Server to connect to vCenter Server to communicate with the vCenter API
Orchestrator8282TCPVCO Client PCVCO ServerHTTP server port – Port used by the HTTP connector to connect to the Web frontend.
Orchestrator8283TCPVCO Client PCVCO ServerHTTPS server port – Port used by HTTP connector to connect to the Web frontend. Requires Jetty to be configured for SSL.
Stage Manager#137UDPESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs
Stage Manager138UDPESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs
Stage Manager139TCPESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs
Stage Manager389TCP/UDPStage Manager ServerLDAP ServerLDAP Authentication (optional)
Stage Manager443TCPClient PCStage Manager ServerStage Manager Console (Web Browser)
Stage Manager443TCPStage Manager ServerESX HostStage Manager Server communication with ESX Host Agent
Stage Manager443TCPStage Manager ServervCenter ServerStage Manager Server communication with vCenter Server
Stage Manager445TCPESX HostSMB File ServerSMB File Sharing for Importing/Exporting VMs
Stage Manager514TCPStage Manager ServerESX HostESX Host Virtual Router
Stage Manager636TCPStage Manager ServerLDAP ServerLDAPS Authentication (optional)
Stage Manager5212TCPStage Manager ServerESX HostStage Manager Agent
Update Manager#80TCPUpdate Manager Serverwww.vmware.com and xml.shavlik.comTo obtain metadata for the updates, Update Manager must be able to connect to http://www.vmware.com and http://xml.shavlik.com
Update Manager80TCPESXi/ESX HostUpdate Manager HostESXi/ESX Host to Update Manager Server. The reverse proxy forwards the request to port 9084
Update Manager80TCPUpdate Manager ServervCenter ServerUpdate Manager to vCenter Server communication
Update Manager443TCPUpdate Manager Serverwww.vmware.com and xml.shavlik.comTo obtain metadata for the updates, Update Manager must be able to connect to http://www.vmware.com and http://xml.shavlik.com
Update Manager443TCPESXi/ESX HostUpdate Manager ServerESXi/ESX Host to Update Manager Server . The reverse proxy forwards the request to port 9084
Update Manager443TCPvCenter ServerUpdate Manager ServervCenter Server to Update Manager Server. The reverse proxy forwards the request to port 8084
Update Manager735TCPUpdate Manager ServerVirtual MachinesUpdate Managerlistenerport (rdevServer.exe) part of theRemote Device Server used for virtual machine patching.
Update Manager902TCPUpdate Manager ServerESXi/ESX HostTo push patches and updates from Update Manager to the ESXi/ESX Hosts to be updated
Update Manager1433TCPUpdate Manager ServerMicrosoft SQL ServerUpdate Manager to Microsoft SQL Server connectivity (for UM Database)
Update Manager1521TCPUpdate Manager ServerOracle Database ServerUpdate Manager to Oracle connectivity (for UM Database)
Update Manager8084TCPUpdate Manager ServervCenter ServerSOAP between components of Update Manager Server and the vCenter Update Manager client plug-in. Configurable at install.
Update Manager9084TCPESXi/ESX hostUpdate Manager ServerESXi/ESX hosts connect to the VUM (VMware Update Manager) webserver listening for updates. Configurable at install.
Update Manager9087TCPUpdate Manager ServervCenter ServerPort used for uploading host update files. Configurable at install.
Update Manager9000 to 9100TCPESXi/ESX HostUpdate Manager ServerThis is the recommend port range from which to choose ports for Update Manager if ports 80 and 443 are already in use. Update Manager automatically opens these ports for ESX Host scanning and remediation.
vCenter 2.5.x#25TCPvCenter ServerSMTP ServerEmail notifications
vCenter 2.5.x53UDPvCenter ServerDNS ServerDNS lookups
vCenter 2.5.x80TCPClient PCvCenter ServerRedirect Web Browser to HTTPS Service (443)
vCenter 2.5.x88TCPvCenter ServerActive Directory ServerAD Authentication
vCenter 2.5.x88UDPvCenter ServerActive Directory ServerAD Authentication
vCenter 2.5.x161UDPSNMP ServervCenter ServerSNMP Polling
vCenter 2.5.x162UDPvCenter ServerSNMP ServerSNMP Trap Send
vCenter 2.5.x389TCP/UDPvCenter ServerLDAP ServerLDAP Authentication
vCenter 2.5.x443TCPvCenter ServerESXi/ESX HostvCenter Agent
vCenter 2.5.x443TCPClient PCvCenter ServerVI Web Access (Web Browser)
vCenter 2.5.x443TCPVI / vSphere ClientvCenter ServerVI / vSphere Client access to vCenter Server
vCenter 2.5.x445TCPvCenter ServerActive Directory ServerAD Authentication
vCenter 2.5.x445UDPvCenter ServerActive Directory ServerAD Authentication
vCenter 2.5.x902TCP/UDPvCenter ServerESXi/ESX HostHeartbeat
vCenter 2.5.x902TCP/UDPESXi/ESX HostvCenter ServerHeartbeat
vCenter 2.5.x903TCPClient PCvCenter ServerVI / vSphere Client to VM Console
vCenter 2.5.x903TCPvCenter ServerESXi/ESX HostVI / vSphere Client to VM Console (after connection established between VI / vSphere Client and vCenter)
vCenter 2.5.x1433TCPvCenter ServerMicrosoft SQL ServerFor vCenter Microsoft SQL Server Database
vCenter 2.5.x1521TCPvCenter ServerOracle Database ServerFor vCenter Oracle Database
vCenter 2.5.x5989TCPVirtualCenter/vCenterESXi/ESX HostvCenter to ESX
vCenter 2.5.x5989TCPESXi/ESX HostVirtualCenter/vCenterESX to vCenter
vCenter 2.5.x8005TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 2.5.x8006TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 2.5.x8083TCPvCenter ServervCenter ServerInternal Service Diagnostics
vCenter 2.5.x8085TCPvCenter ServervCenter ServerInternal Service Diagnostics/SDK
vCenter 2.5.x8086TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 2.5.x8087TCPvCenter ServervCenter ServerInternal Service Diagnostics
vCenter 2.5.x27000TCPvCenter ServerVMware License ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 2.5.x27000TCPVMware License ServervCenter ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 2.5.x27010TCPvCenter ServerVMware License ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 2.5.x27010TCPVMware License ServervCenter ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 4.x25TCPvCenter ServerSMTP ServerEmail notifications
vCenter 4.x#53UDPvCenter ServerDNS ServerDNS lookups
vCenter 4.x80TCPClient PCvCenter ServerRedirect Web Browser to HTTPS Service (443)
vCenter 4.x80TCPvCenter ServerESXi/ESX 4.xDPM with IPMI (iLO/BMC) ASF Remote Management and Control Protocol
vCenter 4.x88UDPvCenter ServerActive Directory ServerAD Authentication
vCenter 4.x88TCPvCenter ServerActive Directory ServerAD Authentication
vCenter 4.x135TCPvCenter ServervCenter ServerLinked Mode
vCenter 4.x161UDPSNMP ServervCenter ServerSNMP Polling
vCenter 4.x162UDPvCenter ServerSNMP ServerSNMP Trap Send
vCenter 4.x389TCP/UDPvCenter ServerLinked vCenter ServersBi-directional LDAP authentication with Kerberos encryption on TCP port 389 is required between all vCenters that need to replicate.
vCenter 4.x443TCPvCenter ServerESXi/ESX HostvCenter Agent
vCenter 4.x443TCPvCenter ServerESXi/ESX 4.xHost DPM with HP iLO Remote Management and Control Protocol
vCenter 4.x443TCPClient PCvCenter ServerVI Web Access (Web Browser)
vCenter 4.x443TCPvSphere ClientvCenter ServervSphere Client access to vCenter Server
vCenter 4.x445TCPvCenter ServerActive Directory ServerAD Authentication
vCenter 4.x445UDPvCenter ServerActive Directory ServerAD Authentication
vCenter 4.x623UDPvCenter ServerESXi/ESX 4.x HostDPM with IPMI (iLO/BMC) ASF Remote Management and Control Protocol
vCenter 4.x636TCPvCenter ServerLinked vCenter ServersLinked mode connectivity between vCenter Servers
vCenter 4.x902TCP/UDPvCenter ServerESXi/ESX HostHeartbeat
vCenter 4.x902TCP/UDPESXi/ESX HostvCenter ServerHeartbeat
vCenter 4.x903TCPClient PCvCenter ServerVI / vSphere Client to VM Console
vCenter 4.x902TCPvCenter ServerESXi/ESX HostVI / vSphere Client to VM Console (after connection established between VI / vSphere Client and vCenter)
vCenter 4.x1024 (dynamic)RPCLinked vCenter ServersLinked vCenter ServersBi-directional RPC communication on dynamic TCP ports is required between all vCenters that need to replicate (via ADAM). A VIC still needs a direct connection to all vCenters that own an object it needs to manage.
vCenter 4.x1433TCPvCenter ServerMicrosoft SQL ServerFor vCenter Microsoft SQL Server Database
vCenter 4.x1521TCPvCenter ServerOracle Database ServerFor vCenter Oracle Database
vCenter 4.x5989TCPvCenter ServerESXi/ESX HostvCenter to ESX
vCenter 4.x5989TCPESXi/ESX HostvCenter ServerESX to vCenter
vCenter 4.x8005TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 4.x8006TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 4.x8080TCPClient PCvCenter Server 4.xVMware vCenter 4 Management Web Services - HTTP
vCenter 4.x8083TCPvCenter ServervCenter ServerInternal Service Diagnostics
vCenter 4.x8085TCPvCenter ServervCenter ServerInternal Service Diagnostics/SDK
vCenter 4.x8086TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 4.x8087TCPvCenter ServervCenter ServerInternal Service Diagnostics
vCenter 4.x8089TCPvCenter ServervCenter ServerSDK Tunneling Port
vCenter 4.x8443TCPClient PCvCenter Server 4.xVMware vCenter 4 Management Web Services - HTTPS
vCenter 4.x8443TCPvCenter ServervCenter ServerLinked Mode
vCenter 4.x27000TCPvCenter ServerVMware License ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 4.x27000TCPVMware License ServervCenter ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 4.x27010TCPvCenter ServerVMware License ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 4.x27010TCPVMware License ServervCenter ServerLicensing via FlexLM. Only required by vCenter 4 if ESXi/ESX 3.x Hosts will be supported
vCenter 4.1#60099TCPvCenter ServervCenter Server ServicesThis port is for internal communication between vCenter Server and its solutions. Specifically, it is used to exchange messages about inventory. If you do not have it open, a solution that integrates with vCenter Server using this service may be affected.
vCenter 5.x#25TCPvCenter ServerSMTP ServerEmail notifications
vCenter 5.x53UDPvCenter ServerDNS ServerDNS lookups
vCenter 5.x80TCPClient PCvCenter ServervCenter Server requires port 80 for direct HTTP connections.
vCenter 5.x80TCPvCenter ServerESXi 5.xDPM with IPMI (iLO/BMC) ASF Remote Management and Control Protocol
vCenter 5.x88UDPvCenter ServerActive Directory ServerAD Authentication
vCenter 5.x88TCPvCenter ServerActive Directory ServerAD Authentication
vCenter 5.x135TCPvCenter ServervCenter ServerLinked Mode
vCenter 5.x161UDPSNMP ServervCenter ServerSNMP Polling
vCenter 5.x162UDPvCenter ServerSNMP ServerSNMP Trap Send
vCenter 5.x389TCP/UDPvCenter ServerLinked vCenter ServersThis is the LDAP port number for the Directory Services for the vCenter Server group. The vCenter Server system needs to bind to port 389, even if you are not joining this vCenter Server instance to a Linked Mode group. If another service is running on this port, you can run the LDAP service on any port from 1025 through 65535.
vCenter 5.x443TCPvSphere ClientvCenter ServervCenter Server system uses to listen for connections from the vSphere Client.
vCenter 5.x443TCPvCenter ServerESXi 5.xvCenter Agent. Host DPM with HP iLO Remote Management and Control Protocol
vCenter 5.x623UDPvCenter ServerESXi 5.xDPM with IPMI (iLO/BMC) ASF Remote Management and Control Protocol
vCenter 5.x636TCPvCenter ServersLinked vCenter ServersvCenter Server Linked Mode, this is the SSL port of the local instance.
vCenter 5.x902TCPvCenter ServerESXi 5.xvCenter Server system uses to send data to managed hosts. This port must not be blocked by firewalls between the server and the hosts or between hosts.
vCenter 5.x902UDPvCenter ServerESXi 5.xManaged hosts send a regular heartbeat to the vCenter Server system. This port must not be blocked by firewalls between the server and the hosts or between hosts.
vCenter 5.x902TCP/UDPvSphere ClientESXi 5.xvSphere Client uses this ports to display virtual machine consoles.
vCenter 5.x902TCP/UDPESXi 5.xESXi 5.xHost access to other hosts for migration and provisioning
vCenter 5.x1024 (dynamic)RPCLinked vCenter ServersLinked vCenter ServersBi-directional RPC communication on dynamic TCP ports is required between all vCenters that need to replicate (via ADAM). A VIC still needs a direct connection to all vCenters that own an object it needs to manage.
vCenter 5.x1433TCPvCenter ServerMicrosoft SQL ServerFor vCenter Microsoft SQL Server Database
vCenter 5.x1521TCPvCenter ServerOracle Database ServerFor vCenter Oracle Database
vCenter 5.x5988TCPESXi 5.xvCenter ServerCIM transactions over HTTP
vCenter 5.x5989TCPvCenter ServerESXi 5.xCIM XML transactions over HTTPS
vCenter 5.x5989TCPESXi 5.xvCenter ServerCIM XML transactions over HTTPS
vCenter 5.x7500UDPvCenter ServervCenter ServerLinked Mode, Java Discovery Port
vCenter 5.x8005TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 5.x8006TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 5.x8009TCPvCenter ServervCenter ServerAJP Port
vCenter 5.x8080TCPClient PCvCenter ServerWeb Services HTTP. Used for the VMware VirtualCenter Management Web Services.
vCenter 5.x8083TCPvCenter ServervCenter ServerInternal Service Diagnostics
vCenter 5.x8085TCPvCenter ServervCenter ServerInternal Service Diagnostics/SDK
vCenter 5.x8086TCPvCenter ServervCenter ServerInternal Communication Port
vCenter 5.x8087TCPvCenter ServervCenter ServerInternal Service Diagnostics
vCenter 5.x8089TCPvCenter ServervCenter ServerSDK Tunneling Port
vCenter 5.x8443TCPClient PCvCenter ServerWeb Services HTTPS. Used for the VMware VirtualCenter Management Web Services.
vCenter 5.x8443TCPvCenter ServervCenter ServerLinked Mode
vCenter 5.x9443TCPClient PCvCenter ServervSphere Web Client Access
vCenter 5.x10109TCPvCenter ServervCenter ServervCenter Inventory Service Service Management
vCenter 5.x10111TCPvCenter ServervCenter ServervCenter Inventory Service Linked Mode Communication
vCenter 5.x10443TCPClient PCvCenter ServervCenter Inventory Service HTTPS
vCenter 5.x51915TCPESXivSphere Authentication ProxyThis is a web service, which is used to add host to Active Directory domain.
vCenter 5.x60099TCPvCenter ServervCenter ServerWeb Service change service notification port
vCenter 5.1#7005TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnBase shutdown port.
For more information, seeConfiguring VMware Tomcat Server Settings in vCenter Server 5.1.
vCenter 5.17080TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnHTTP Port
vCenter 5.17444TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnLookup Service, HTTPS Port
vCenter 5.17009TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnAJP Port
vCenter 5.1/5.5#10109 to 10111TCPvCenter Inventory ServicevCenter ServervCenter Inventory Service Linked Mode Communication
vCenter 5.1/5.58003TCPvCenter Server (Tomcat Server settings)vCenter Server Management Web ServicesvCenter Server Management Web Service shutdown
vCenter 5.149152 to 65535TCPActive DirectoryvCenter ServerAllow Active Directory authentication/communication between domain controllers and vCenter Server.
vCenter 5.5#88TCPvCenter ServervCenter Single Sign-OnKdc Service
vCenter 5.52012TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnDirectory Service
vCenter 5.52013TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnKdc Service
vCenter 5.52014TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnVMware Certificate Service inter-communications with vCenter Single Sign-On
vCenter 5.57331TCPvCenter Server (Tomcat Server settings)vSphere Web ClientHTML5 remote console for virtual machines
vCenter 5.57444TCPvCenter Server (Tomcat Server settings)vCenter Single Sign-OnLookup Service, HTTPS port
vCenter 5.511711TCPvCenter Single Sign-OnvCenter Single Sign-OnDirectory service LDAP use for replication between vCenter Single Sign-On nodes
vCenter 5.511712TCPvCenter Single Sign-OnvCenter Single Sign-OnDirectory service LDAPS use for replication between vCenter Single Sign-On nodes
vCenter 5.512721TCPvCenter Single Sign-OnvCenter Single Sign-OnIdentity Management Service (IDM) internal client/server communication port.
Used by VMware Identity Management Service.
vCenter 5.549000 to 65000TCPActive DirectoryvCenter ServerAllow Active Directory authentication/communication between domain controllers and vCenter Server.
Used by the VMware Identity Management Service
vCenter Infrastructure Navigator 1.x#22TCPClient PCvCenter Infrastructure Navigator ApplianceEnables SSH access to vCenter Infrastructure Appliance
vCenter Infrastructure Navigator 1.x80TCPvCenter Infrastructure NavigatorvSphere Web service APIHTTP web service
vCenter Infrastructure Navigator 1.x443TCPvCenter Infrastructure NavigatorvSphere Web service APIHTTPS web service
vCenter Infrastructure Navigator 1.x443TCPvCenter Infrastructure NavigatorESXi/ESX hosts and virtual machinesVIX protocol on target hosts to perform discovery
vCenter Infrastructure Navigator 1.x902TCPvCenter Infrastructure NavigatorESXi/ESX hosts and virtual machinesVIX protocol on target hosts to perform discovery
vCenter Infrastructure Navigator 1.x2868TCPvCenter ServervCenter Infrastructure NavigatorPlug-in downloads. This download happens as part of the registration process.
vCenter Infrastructure Navigator 1.x6969TCPvCenter ServervCenter Infrastructure NavigatorConnectivity from vSphere Web Client to vCenter Infrastructure Navigator
vCenter Log Insight 1.x#22TCPSSH ClientLog InsightSecure Shell (SSH) access to the vCenter Log Insight virtual appliance
vCenter Log Insight 1.x25TCPLog InsightSMTP ServerEmail notifications from vCenter Log Insight to a configured mail server
vCenter Log Insight 1.x514UDPSyslog ClientLog InsightRemote Syslog logging
vCenter Log Insight 1.x514TCPSyslog ClientLog InsightRemote Syslog logging
vCenter Log Insight 1.x1514TCPSyslog ClientLog InsightSSL Encrypted Remote Syslog logging
vCenter Log Insight 1.x445UDPLog InsightMS Directory Services ServerConnection to a Domain Controller for Active Directory Authentication
vCenter Log Insight 1.x80TCPHTTP ClientLog InsightLog Insight Web Interface. Redirects to encrypted web interface
vCenter Log Insight 1.x443TCPHTTP ClientLog InsightLog Insight Web Interface Encrypted
vCenter Log Insight 1.x123UDPLog InsightNTP ServerTime synchronization with NTP server
vCloud Usage Meter#80TCPvCloud Usage MetervCenter ServerThis is for vSphere API
vCloud Usage Meter443TCPvCloud Usage MetervCenter ServerThis is for vSphere API
vCloud Usage Meter5480TCPvCenter Update ManagervCloud Usage MeterThis is used for virtual appliance updates
vCloud Usage Meter8443TCPClient BrowservCloud Usage MeterThis is for WebApp
vCenter Operations Standard 1.x#22TCPSSH ClientvCenter Operations Standard 1.x virtual applianceEnables SSH access to the vCenter Operations Standard virtual appliance
vCenter Operations Standard 1.x443TCPBrowser or vSphere Client pluginvCenter Operations Standard 1.x virtual applianceHTTPS server port for the vCenter Operations Standard Administration page
vCenter Operations Standard 1.x5480TCPBrowservCenter Operations Standard 1.x virtual applianceHTTPS server port for the VMware Studio Web console to administer the virtual appliance
vCenter Operations Manager (vApp) 5.x#80TCPBrowservCenter Operations Manager UI VMHTTP server port that unconditionally redirects to HTTPS port
vCenter Operations Manager (vApp) 5.x443TCP
  • Browser or vSphere Client plugin
  • vCenter Operations Manager UI VM, vCenter Operations Manager Analytics VM
  • vCenter Operations Manager UI VM
  • vCenter Server
  • HTTPS server port for the vCenter Operations Manager UIs: Administration, vSphere, and Custom
  • UI VM: Registration of vCenter Operations Manager as an extension to vCenter, Analytics VM: Collecting metric data from vCenter Server.
vCenter Operations Manager (vApp) 5.x22TCPSSH ClientvCenter Operations Manager UI VM, vCenter Operations Manager Analytics VMEnables SSH access to the vCenter Operations Manager virtual appliance
vCenter Operations Manager (vApp) 5.x1194TCPvCenter Operations Manager Analytics VMvCenter Operations Manager UI VMOpen VPN tunnel for communication between the two VMs
vCenter Operations Manager (Standalone) 5.x#443TCPvCenter Operations Manager UI VM, vCenter Operations Manager Analytics VMvCenter ServerUI VM: Registration of vCenter Operations Manager as an extension to vCenter, Analytics VM: Collecting metric data from vCenter
vCenter Operations Manager (Standalone) 5.x80TCPBrowservCenter Operations Manager (Standalone)(If chosen during configuration) HTTP port to access vCenter Operations Manager UI
vCenter Operations Manager (Standalone) 5.x443TCPBrowservCenter Operations Manager (Standalone)(If chosen during configuration) HTTPS port to access vCenter Operations Manager UI
vCenter Operations Manager (Standalone) 5.x1199TCPvCenter Operations Manager remote collectorvCenter Operations Manager (Standalone)Heartbeat connection between remote collector and main vCenter Operations Manager server
vCenter Operations Manager (Standalone) 5.x61616TCPvCenter Operations Manager remote collectorvCenter Operations Manager (Standalone)Connection between remote collector and ActiveMQ component on the main vCenter Operations Manager server
vCenter Operations Manager (Standalone) 5.x443TCPvCenter Operations Manager local/remote collectorvCenter ServerConnection between remote collector and ActiveMQ component on the main vCenter Operations Manager server
View 3.x#3389TCPThin ClientESX hostRDP Protocol
View 3.x18443TCPView Connection Server/View ManagervCenter ServerView Composer
View 3.x32111TCPView Agent (Virtual Desktop)View ClientUSB Device Communication
View 3.x32111TCPView ClientView Agent (Virtual Desktop)USB Device Communication
View 4.0.x#902TCPView Client/View Client with Offline DesktopESX Host(Optional) View Client with Offline Desktop data is downloaded and uploaded through this port.
View 4.0.x3268TCPView/VDM Connection Server/View ManagerActive Directory ServerGlobal Catalog Server
View 4.0.x3269TCPView/VDM Connection Server/View ManagerActive Directory ServerGlobal Catalog Server
View 4.0.x3389TCPThin ClientESX hostRDP Protocol
View 4.0.x9427TCPView Client/View Client with Offline DesktopView Agent (Virtual Desktop)(Optional) Multimedia Redirection (MMR). MMR is supported by View Client and View Client with Offline Desktop on certain operating systems.
View 4.0.x18443TCPView Connection Server/View ManagervCenter ServerView Composer
View 4.0.x50002TCP/UDPView Agent (Virtual Desktop)View ClientPCoIP (AES 128-bit encryption)
View 4.0.x50002TCP/UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View 4.5.x#----For more information, seeNetwork connectivity requirements for VMware View Manager 4.5 and later (1027217).
View 4.5.x80/443TCPView Client with Local ModeView Transfer ServerHTTP(S) access via direct connection for downloading and uploading Local Mode data
View 4.5.x80/443TCPSecurity ServerView Transfer ServerHTTP(S) access via tunnel connection for downloading and uploading Local Mode data
View 4.5.x902TCPView Connection ServerESX HostUsed when checking out local desktops. Must be accessible on your ESX host when using View Client with Local Mode.
View 4.5.x902TCPView Transfer ServerESX HostPublishing View Composer packages for Local Mode
View 4.5.x4001TCPView Connection ServerView Transfer ServerRequired by JMS for Local Mode
View 4.5.x4172TCP/UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View 4.5.x50002UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View 4.6.x#----For more information, seeNetwork connectivity requirements for VMware View Manager 4.5 and later (1027217).
View 4.6.x80/443TCPView Client with Local ModeView Transfer ServerHTTP(S) access via direct connection for downloading and uploading Local Mode data
View 4.6.x80/443TCPSecurity ServerView Transfer ServerHTTP(S) access via direct connection for downloading and uploading Local Mode data
View 4.6.x902TCPView Connection ServerESX HostUsed when checking out local desktops. Must be accessible on your ESX host when using View Client with Local Mode.
View 4.6.x902TCPView Transfer ServerESX HostPublishing View Composer packages for Local Mode
View 4.6.x4001TCPView Connection ServerView Transfer ServerRequired by JMS for Local Mode
View 4.6.x4172TCP/UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View 4.6.x50002UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View 5.x#----For more information, seeNetwork connectivity requirements for VMware View Manager 4.5 and later (1027217).
View 5.x80/443TCPView Client with Local ModeView Transfer ServerHTTP(S) access via direct connection for downloading and uploading Local Mode data
View 5.x80/443TCPSecurity ServerView Transfer ServerHTTP(S) access via direct connection for downloading and uploading Local Mode data
View 5.x902TCPView Connection ServerESXi HostUsed when checking out local desktops. Must be accessible on your ESXi host when using View Client with Local Mode.
View 5.x902TCPView Transfer ServerESXi HostPublishing View Composer packages for Local Mode
View 5.x902TCPView Composer ServerESXi HostUsed when View Composer customizes linked-clone disks, including View Composer internal disks and, if they are specified, persistent disks and system disposable disks.
View 5.x4001TCPView Connection ServerView Transfer ServerRequired by JMS for Local Mode
View 5.x4172TCP/UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View 5.x50002UDPView ClientView Agent (Virtual Desktop)PCoIP (AES 128-bit encryption)
View/VDM 2.x80TCPView/VDM ClientView/VDM Security ServerVDM Access (not required if only HTTPS is to be supported)
View/VDM 2.x#80TCPClient PCView/VDM Security ServerVDM Web Access (not required if only HTTPS is to be supported). The Security Server used as a proxy in a DMZ to allow for external connections in. The View Manager/Connection Broker has an ADAM instance on it.
View/VDM 2.x80TCPView/VDM ClientView/VDM Connection ServerVDM Access (not required if only HTTPS is to be supported)
View/VDM 2.x80TCPClient PCView/VDM Connection ServerVDM Web Access (not required if only HTTPS is to be supported).
View/VDM 2.x88UDPView/VDM Connection Server/View ManagerActive Directory ServerAD Authentication
View/VDM 2.x88TCPView/VDM Connection Server/View ManagerActive Directory ServerAD Authentication
View/VDM 2.x389TCP/UDPView/VDM Connection Server/View ManagerLDAP ServerLDAP Authentication
View/VDM 2.x443TCPView/VDM ClientView/VDM Security ServerVDM Access
View/VDM 2.x443TCPClient PCView/VDM Connection Server/View ManagerVDM Web Access and VDM Administration
View/VDM 2.x443TCPThin ClientView/VDM Connection Server/View ManagerVDM API
View/VDM 2.x443TCPView/VDM ClientView/VDM Connection Server/View ManagerVDM Access
View/VDM 2.x443TCPClient PCView/VDM Security ServerVDM Web Access (Web Browser)
View/VDM 2.x443TCPView/VDM Connection Server/View ManagervCenter ServerVDM to vCenter communication
View/VDM 2.x445UDPView/VDM Connection Server/View ManagerActive Directory ServerAD Authentication
View/VDM 2.x445TCPView/VDM Connection Server/View ManagerActive Directory ServerAD Authentication
View/VDM 2.x1024 to 65535TCPView/VDM Connection Server/View ManagerVirtual Desktop VM (View/VDM Agent)Ephemeral Ports. A short-lived connection between View Manager and the virtual desktop
View/VDM 2.x1024 to 65535TCPView/VDM Connection Server/View ManagerView/VDM Connection Server/View ManagerThis is required for ADAM replication between VDM Connection Servers. With a Registry entry, this can be fixed to a defined set of ports, but by default it is a random TCP high port
View/VDM 2.x3389TCPView/VDM Security ServerVirtual Desktop VM (View/VDM Agent)Tunneled RDP Connection (RSA RC4 encryption, can be set High/Medium/Low)

High: Encrypts both the data sent from client to server and the data sent from server to client using a 128-bit key.

Medium: Encrypts both the data sent from client to server and the data sent from server to client using a 56-bit key if the client is a Windows 2000 or above client, or a 40-bit key if the client is an earlier version.

Low: Encrypts only the data sent from client to server, using either a 56- or 40-bit key, depending on the client version. Useful to protect usernames and passwords sent from client to server.
View/VDM 2.x3389TCPClient PC/Thin Client/View/VDM ClientVirtual Desktop VM (View/VDM Agent)Direct RDP Connection (RSA RC4 encryption, can be set High/Medium/Low).

High: Encrypts both the data sent from client to server and the data sent from server to client using a 128-bit key.

Medium: Encrypts both the data sent from client to server and the data sent from server to client using a 56-bit key if the client is a Windows 2000 or above client, or a 40-bit key if the client is an earlier version.

Low: Encrypts only the data sent from client to server, using either a 56- or 40-bit key, depending on the client version. Useful to protect usernames and passwords sent from client to server.
View/VDM 2.x4001TCPView/VDM Security ServerView/VDM Connection Server/View ManagerJava Messenger Service (JMS)
View/VDM 2.x4001TCPView/VDM Connection Server/View ManagerView/VDM Security ServerJava Messenger Service (JMS)
View/VDM 2.x4001TCPVirtual Desktop VM (View/VDM Agent)View/VDM Connection Server/View ManagerJava Messenger Service (JMS)
View/VDM 2.x4100TCPView/VDM Connection Server/View ManagerView/VDM Connection Server/View ManagerJava Messenger Service (JMS) inter-router traffic
View/VDM 2.x8009TCPView/VDM Security ServerView/VDM Connection Server/View ManagerApache Jserv Protocol (AJP)
View/VDM 2.x8009TCPView/VDM Connection Server/View ManagerView/VDM Security ServerApache Jserv Protocol (AJP)
View/VDM 2.x42966TCPView Client/View Client with Offline DesktopESX Host(Optional) Hewlett-Packard RGS Sender Application is the server-side component of the HP RGS remote display protocol
VMware vCenter Chargeback 1.5#8080TCPVMWare vCenter Chargeback ServerClientHTTP
VMware vCenter Chargeback 1.58009TCPVMWare vCenter Chargeback ServerClientLoad Balancer
VMware vCenter Chargeback 1.5443TCPVMWare vCenter Chargeback ServerClientHTTPS
VMware vCenter Chargeback 1.525TCPVMWare vCenter Chargeback ServerClientSMTP
VMware vCenter Chargeback 1.5389TCP/UDPVMWare vCenter Chargeback ServerClientLDAP
Virtual SAN#2233TCPESXi hostESXi hostInter Node Communication port
Virtual SAN12345UDPESXi hostESXi hostCluster Management – Multicast
Virtual SAN23451UDPESXi hostESXi hostCluster Management – Multicast
Virtual SAN8080TCPVMware vSphere Profile-Driven Storage ServiceESXi hostVirtual SAN VASA Provider
vShield 1.x22TCPvShield ManagervShield agentSSH traffic passing from vShield Manager to vShield agents
vShield 1.x#123UDPvShield Time SynchronizationvShield Manager (NTP Server)NTP time synchronization with vShield Manager server
vShield 1.x443TCPWeb browser/Client accessvShield ManagerWeb browser using HTTPS to access vShield Manager user interface
vShield 1.x1162UDPvShield ZonesvShield ManagerSends SNMP trap messages from vShield agents to vShield Manager
vShield 4.x#22TCPvShield ManagervShield agentSSH traffic passing from vShield Manager to vShield agents
vShield 4.x123UDPvShield Time SynchronizationvShield Manager (NTP Server)NTP time synchronization with vShield Manager server
vShield 4.x443TCPWeb browser/Client accessvShield ManagerWeb browser using HTTPS to access vShield Manager user interface
vShield 4.x1162UDPvShield ZonesvShield ManagerSends SNMP trap messages from vShield agents to vShield Manager
vSphere Management Assistant#443TCPvSphere Management AssistantESX HostFor SDK traffic


VI / vSphere Client ports:

ProductPortProtocolSourceTargetPurpose
Data Recovery22024TCPData Recovery vSphere Client Plug-inData Recovery ApplianceData Recovery management
ESX 3.x80TCPVI / vSphere clientESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESX 3.x443TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX Host management connection
ESX 3.x902TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX hosted VM connectivity (MKS)
ESX 3.x903TCPVI / vSphere clientESXi/ESX HostVM Remote Console
ESX 4.x80TCPVI / vSphere clientESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESX 4.x443TCPvSphere ClientESXi/ESX HostvSphere Client to ESXi/ESX Host management connection
ESX 4.x902TCPvSphere ClientESXi/ESX HostvSphere Client to ESXi/ESX hosted VM connectivity (MKS)
ESX 4.x903TCPVI / vSphere clientESXi/ESX HostVM Remote Console (MKS)
ESXi 3.x80TCPVI / vSphere clientESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESXi 3.x443TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX Host management connection
ESXi 3.x902TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX hosted VM connectivity (MKS/Remote Console)
ESXi 3.x903TCPVI / vSphere clientESXi/ESX HostVM Remote VM Console (MKS)
ESXi 4.x80TCPVI / vSphere clientESXi/ESX HostRedirect Web Browser to HTTPS Service (443)
ESXi 4.x443TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX Host management connection
ESXi 4.x902TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX hosted VM connectivity (MKS/Remote Console)
ESXi 4.x903TCPVI / vSphere clientESXi/ESX HostVM Remote Console (MKS)
ESXi 5.x22TCPvSphere clientESXi 5.xSSH Server
ESXi 5.x80TCPvSphere clientESXi 5.xRedirect Web Browser to HTTPS Service (443)
ESXi 5.x443TCPVI / vSphere clientESXi/ESX HostVI / vSphere client to ESXi/ESX Host management connection
ESXi 5.x902TCPvSphere ClientESXi 5.xvSphere Client access to virtual machine consoles (MKS)
vCenter 2.5.x80TCPVI / vSphere clientvCenter ServerRedirect Web Browser to HTTPS Service (443)
vCenter 2.5.x443TCPVI / vSphere clientvCenter ServerVI / vSphere client access to vCenter Server
vCenter 2.5.x903TCPVI / vSphere clientvCenter ServerVI / vSphere client to VM Console
vCenter 4.x80TCPVI / vSphere clientvCenter ServerRedirect Web Browser to HTTPS Service (443)
vCenter 4.x443TCPvSphere ClientvCenter ServervSphere Client access to vCenter Server
vCenter 4.x903TCPVI / vSphere clientvCenter ServerVI / vSphere client to VM Console
vCenter 4.x8080TCPVI / vSphere clientvCenter Server 4.xVMware vCenter 4 Management Web Services - HTTP
vCenter 4.x8443TCPVI / vSphere clientvCenter Server 4.xVMware vCenter 4 Management Web Services - HTTPS
vCenter 5.x80TCPvSphere clientvCenter ServervCenter Server requires port 80 for direct HTTP connections.
vCenter 5.x443TCPvSphere ClientvCenter ServervCenter Server system uses to listen for connections from the vSphere Client.
vCenter 5.x902TCP/UDPvSphere ClientESXi 5.xvSphere Client uses this ports to display virtual machine consoles.
vCenter 5.x903TCPvSphere ClientESX 3.5 and 4.xRemote console traffic generated by user access to virtual machines. This applies to all ESXi/ESX versions.
vCenter 5.x8080TCPvSphere clientvCenter ServerWeb Services HTTP. Used for the VMware VirtualCenter Management Web Services.
vCenter 5.x8443TCPvSphere clientvCenter ServerWeb Services HTTPS. Used for the VMware VirtualCenter Management Web Services.
vCenter 5.x9443TCPvSphere clientvCenter ServervSphere Web Client Access
vCenter 5.x10080TCPvSphere clientvCenter ServervCenter Inventory Service HTTP
vCenter 5.x10443TCPvSphere clientvCenter ServervCenter Inventory Service HTTPS

No comments:

Post a Comment