Какие порты использует VMware
Как и какие порты использует VMware, Converter, AppSpeed, Consolidated Backup, Data Recovery, ESX, Heartbeat, Guided Consolidation, Lab Manager, Orchestrator.
AppSpeed
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
AppSpeed | 80 | TCP | AppSpeed Server | vCenter Server 4 | vCenter proxy interface. Used only during setup to verify the proxy is setup correctly. Port 80 is the default Web Service Port, but a different TCP port can be configured in vCenter Server 4. |
AppSpeed | 443 | TCP | AppSpeed Server | vCenter Server 4 | Default port for communications. A different TCP port can be configured in vCenter Server 4. |
AppSpeed | 22 | TCP | AppSpeed Server | AppSpeed Probe | Connections to the probes to access the probes outside of the VPN. |
AppSpeed | 123 | TCP | AppSpeed Server | AppSpeed Probe | NTP services |
AppSpeed | 1194 | TCP/UDP | AppSpeed Server | AppSpeed Probe | Communications over OpenVPN |
Consolidated Backup
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Consolidated Backup | 443 | TCP | VCB Proxy Server | vCenter Server | Required for VCB and vcbMounter communication and backup processes |
Consolidated Backup | 443 | TCP | VCB Proxy Server | ESX/ESXi Host | Required for VCB and vcbMounter communication and backup processes |
Converter
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Converter 3.x | 137 | UDP | vCenter Converter Server | Source Computer to be converted | For hot migration. Not required if the source computer does not use NetBIOS |
Converter 3.x | 138 | UDP | vCenter Converter Server | Source Computer to be converted | For hot migration. Not required if the source computer does not use NetBIOS |
Converter 3.x | 139 | TCP | vCenter Converter Server | Source Computer to be converted | For hot migration. Not required if the source computer does not use NetBIOS |
Converter 3.x | 443 | TCP | Source Computer to be converted | ESX/ESXi Host | Required for destination VM access when target is ESX/ESXi/vCenter |
Converter 3.x | 443 | TCP | Source Computer to be converted | vCenter Server | Required if vCenter Server is the conversion target |
Converter 3.x | 443 | TCP | vCenter Converter Server | vCenter Server | Required if vCenter Server is the conversion target |
Converter 3.x | 443 | TCP | vCenter Converter Server | ESX/ESXi Host | Required for system conversion |
Converter 3.x | 445 | TCP | vCenter Converter Server | Source Computer to be converted | Required for system conversion. Not required if the source computer uses NetBIOS |
Converter 3.x | 902 | TCP | Source Computer to be converted | ESX/ESXi Host | Required for data transport during cloning of system to be converted to target ESX/ESXi Host |
Converter 4.x | 22 | TCP | Helper Virtual Machine | Source Computer to be converted | Required for conversion of Linux-based source computers (data flows from source to VM) |
Converter 4.x | 22 | TCP | vCenter Converter Server | Source Computer to be converted | Required for conversion of Linux-based source computers |
Converter 4.x | 137 | UDP | vCenter Converter Server | Source Computer to be converted | For hot migration. Not required if the source computer does not use NetBIOS |
Converter 4.x | 138 | UDP | vCenter Converter Server | Source Computer to be converted | For hot migration. Not required if the source computer does not use NetBIOS |
Converter 4.x | 139 | TCP | vCenter Converter Server | Source Computer to be converted | For hot migration. Not required if the source computer does not use NetBIOS |
Converter 4.x | 443 | TCP | vCenter Converter Client | vCenter Converter Server | Only required if the Converter Client and Converter Server were installed on different systems |
Converter 4.x | 443 | TCP | Source Computer to be converted | ESX/ESXi Host | Required for destination VM access when target is ESX/ESXi/vCenter |
Converter 4.x | 443 | TCP | Source Computer to be converted | vCenter Server | Required if vCenter Server is the conversion target |
Converter 4.x | 443 | TCP | vCenter Converter Server | vCenter Server | Required if vCenter Server is the conversion target |
Converter 4.x | 443 | TCP | vCenter Converter Server | ESX/ESXi Host | Required for system conversion |
Converter 4.x | 443 | TCP | vCenter Converter Server | Helper Virtual Machine | Required for conversion of Linux-based source computers |
Converter 4.x | 445 | TCP | vCenter Converter Server | Source Computer to be converted | Required for system conversion. Not required if the source computer uses NetBIOS |
Converter 4.x | 902 | TCP | Source Computer to be converted | ESX/ESXi Host | Required for data transport during cloning of system to be converted to target ESX/ESXi Host |
Converter 4.x | 9089, 9090 | TCP | vCenter Converter Server | Source Computer to be converted | Required for system conversion. Remote agent deployment |
Data Recovery
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Data Recovery | 443 | TCP | Data Recovery Appliance | vCenter Server | VDR to vCenter Server communications |
Data Recovery | 902 | TCP | Data Recovery Appliance | ESX Host | VDR to ESX communications |
Data Recovery | 22024 | TCP | Data Recovery vSphere Client Plug-in | Data Recovery Appliance | Data Recovery management |
ESX
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
ESX 3.x | 21 | TCP | FTP Client | ESX Host | FTP |
ESX 3.x | 21 | TCP | ESX Host | FTP Server | FTP |
ESX 3.x | 22 | TCP | SSH Client | ESX Host | SSH |
ESX 3.x | 22 | TCP | ESX Host | SSH Server | SSH |
ESX 3.x | 53 | UDP | ESX/ESXi Host | DNS Server | DNS |
ESX 3.x | 80 | TCP | Client PC | ESX/ESXi Host | Redirect Web Browser to HTTPS Service (443) |
ESX 3.x | 88 | TCP | ESX Host | Active Directory Server | PAM Active Directory Authentication - Kerberos |
ESX 3.x | 111 | UDP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESX 3.x | 111 | TCP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESX 3.x | 123 | UDP | ESX/ESXi Host | NTP Time Server | NTP Client |
ESX 3.x | 137 - 139 | TCP | ESX Host | SMB Server | SMB |
ESX 3.x | 161 | UDP | SNMP Server | ESX Host | SNMP Polling |
ESX 3.x | 162 | UDP | ESX Host | SNMP Collector | SNMP Trap Send |
ESX 3.x | 389 | TCP | ESX Host | LDAP Server | PAM Active Directory Authentication – LDAP |
ESX 3.x | 427 | UDP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESX 3.x | 427 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESX 3.x | 443 | TCP | Client PC | ESX Host | Host VI Management via web browser |
ESX 3.x | 443 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi Host management connection |
ESX 3.x | 443 | TCP | ESX/ESXi Host | ESX/ESXi Host | Host to host VM migration and provisioning |
ESX 3.x | 445 | TCP | ESX Host | SMB Server | SMB |
ESX 3.x | 445 | TCP | ESX Host | MS Directory Services Server | PAM Active Directory Authentication |
ESX 3.x | 445 | UDP | ESX Host | MS Directory Services Server | PAM Active Directory Authentication |
ESX 3.x | 464 | TCP | ESX Host | Active Directory Server | PAM Active Directory Authentication – Kerberos Password Services |
ESX 3.x | 514 | UDP | ESX/ESXi Host | Syslog Server | Remote syslog logging |
ESX 3.x | 902 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi hosted VM connectivity |
ESX 3.x | 902 | TCP/UDP | ESX/ESXi Host | ESX/ESXi Host | Authentication, Provisioning, VM Migration |
ESX 3.x | 902 | TCP/UDP | ESX/ESXi Host | vCenter 4 Server | Heartbeat |
ESX 3.x | 903 | TCP | VI/vSphere Client | ESX/ESXi Host | VM Remote VM Console |
ESX 3.x | 2049 | UDP | ESX/ESXi Host | NFS Server | NFS Client |
ESX 3.x | 2049 | TCP | ESX/ESXi Host | NFS Server | NFS Client |
ESX 3.x | 2050 - 2250 | UDP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESX 3.x | 3260 | TCP | ESX/ESXi Host | iSCSI SAN | Software iSCSI Client and Hardware iSCSI HBA |
ESX 3.x | 5988 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESX 3.x | 5989 | TCP | ESX/ESXi Host | VirtualCenter/vCenter | CIM Secure Server to CIM Client |
ESX 3.x | 5989 | TCP | VirtualCenter/vCenter | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESX 3.x | 8000 | TCP | ESX/ESXi Host (VM Target) | ESX/ESXi Host (VM Source) | VMotion Communication on VMKernel Interface |
ESX 3.x | 8000 | TCP | ESX/ESXi Host (VM Source) | ESX/ESXi Host (VM Target) | VMotion Communication on VMKernel Interface |
ESX 3.x | 8042 -8045 | TCP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESX 3.x | 27000 | TCP | ESX/ESXi Host | VMware License Server | ESX/ESXi 3.x Host to License Server communication |
ESX 3.x | 27010 | TCP | ESX/ESXi Host | VMware License Server | ESX/ESXi 3.x Host to License Server communication |
ESX 4.x | 21 | TCP | FTP Client | ESX Host | FTP |
ESX 4.x | 21 | TCP | ESX Host | FTP Server | FTP |
ESX 4.x | 22 | TCP | ESX Host | SSH Server | SSH |
ESX 4.x | 22 | TCP | SSH Client | ESX Host | SSH |
ESX 4.x | 53 | UDP | ESX/ESXi Host | DNS Server | DNS |
ESX 4.x | 80 | TCP | Client PC | ESX/ESXi Host | Redirect Web Browser to HTTPS Service (443) |
ESX 4.x | 88 | TCP | ESX Host | Active Directory Server | PAM Active Directory Authentication - Kerberos |
ESX 4.x | 111 | UDP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESX 4.x | 111 | TCP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESX 4.x | 123 | UDP | ESX/ESXi Host | NTP Time Server | NTP Client |
ESX 4.x | 137 - 139 | TCP | ESX Host | SMB Server | SMB |
ESX 4.x | 161 | UDP | SNMP Server | ESX Host | SNMP Polling |
ESX 4.x | 162 | UDP | ESX Host | SNMP Collector | SNMP Trap Send |
ESX 4.x | 389 | TCP | ESX Host | LDAP Server | PAM Active Directory Authentication – LDAP |
ESX 4.x | 427 | UDP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESX 4.x | 427 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESX 4.x | 443 | TCP | ESX/ESXi Host | ESX/ESXi Host | Host to host VM migration and provisioning |
ESX 4.x | 443 | TCP | Client PC | ESX Host | Host VI Management via web browser |
ESX 4.x | 443 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi Host management connection |
ESX 4.x | 445 | UDP | ESX Host | MS Directory Services Server | PAM Active Directory Authentication |
ESX 4.x | 445 | TCP | ESX Host | SMB Server | SMB |
ESX 4.x | 445 | TCP | ESX Host | MS Directory Services Server | PAM Active Directory Authentication |
ESX 4.x | 464 | TCP | ESX Host | Active Directory Server | PAM Active Directory Authentication – Kerberos Password Services |
ESX 4.x | 514 | UDP | ESX/ESXi Host | Syslog Server | Remote syslog logging |
ESX 4.x | 902 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi hosted VM connectivity |
ESX 4.x | 902 | TCP/UDP | ESX/ESXi Host | ESX/ESXi Host | Authentication, Provisioning, VM Migration |
ESX 4.x | 902 | TCP/UDP | ESX/ESXi Host | vCenter 4 Server | Heartbeat |
ESX 4.x | 903 | TCP | VI/vSphere Client | ESX/ESXi Host | VM Remote VM Console |
ESX 4.x | 2049 | UDP | ESX/ESXi Host | NFS Server | NFS Client |
ESX 4.x | 2049 | TCP | ESX/ESXi Host | NFS Server | NFS Client |
ESX 4.x | 2050 - 2250 | UDP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESX 4.x | 3260 | TCP | ESX/ESXi Host | iSCSI SAN | Software iSCSI Client and Hardware iSCSI HBA |
ESX 4.x | 5900 - 5964 | TCP | ESX/ESXi Host | ESX/ESXi Host | RFB Protocol used by management tools such as VNC |
ESX 4.x | 5988 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESX 4.x | 5989 | TCP | VirtualCenter/vCenter | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESX 4.x | 5989 | TCP | ESX/ESXi Host | VirtualCenter/vCenter | CIM Secure Server to CIM Client |
ESX 4.x | 8000 | TCP | ESX/ESXi Host (VM Target) | ESX/ESXi Host (VM Source) | VMotion Communication on VMKernel Interface |
ESX 4.x | 8000 | TCP | ESX/ESXi Host (VM Source) | ESX/ESXi Host (VM Target) | VMotion Communication on VMKernel Interface |
ESX 4.x | 8042 - 8045 | TCP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESX 4.x | 47 | UDP | ESX/ESXi Host | Physical Switches | vDS (Virtual Distributed Switch) Broadcast |
ESX 4.x | 8100 | TCP/UDP | ESX/ESXi 4 Host | ESX/ESXi 4.x Host | VMware Fault Tolerance. ESX/ESXi 4 only. |
ESX 4.x | 8200 | TCP/UDP | ESX/ESXi 4 Host | ESX/ESXi 4.x Host | VMware Fault Tolerance. ESX/ESXi 4 only. |
ESXi 3.x | 53 | UDP | ESX/ESXi Host | DNS Server | DNS |
ESXi 3.x | 80 | TCP | Client PC | ESX/ESXi Host | Redirect Web Browser to HTTPS Service (443) |
ESXi 3.x | 111 | TCP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESXi 3.x | 111 | UDP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESXi 3.x | 123 | UDP | ESX/ESXi Host | NTP Time Server | NTP Client |
ESXi 3.x | 162 | UDP | ESX Host | SNMP Collector | SNMP Trap Send |
ESXi 3.x | 427 | UDP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESXi 3.x | 427 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESXi 3.x | 443 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi Host management connection |
ESXi 3.x | 443 | TCP | ESX/ESXi Host | ESX/ESXi Host | Host to host VM migration and provisioning |
ESXi 3.x | 514 | UDP | ESX/ESXi Host | Syslog Server | Remote syslog logging |
ESXi 3.x | 902 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi hosted VM connectivity |
ESXi 3.x | 902 | TCP/UDP | ESX/ESXi Host | ESX/ESXi Host | Authentication, Provisioning, VM Migration |
ESXi 3.x | 902 | TCP/UDP | ESX/ESXi Host | vCenter 4 Server | Heartbeat |
ESXi 3.x | 903 | TCP | VI/vSphere Client | ESX/ESXi Host | VM Remote VM Console |
ESXi 3.x | 2049 | TCP | ESX/ESXi Host | NFS Server | NFS Client |
ESXi 3.x | 2049 | UDP | ESX/ESXi Host | NFS Server | NFS Client |
ESXi 3.x | 2050 - 2250 | UDP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESXi 3.x | 3260 | TCP | ESX/ESXi Host | iSCSI SAN | Software iSCSI Client and Hardware iSCSI HBA |
ESXi 3.x | 5988 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESXi 3.x | 5989 | TCP | VirtualCenter/vCenter | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESXi 3.x | 5989 | TCP | ESX/ESXi Host | VirtualCenter/vCenter | CIM Secure Server to CIM Client |
ESXi 3.x | 8000 | TCP | ESX/ESXi Host (VM Target) | ESX/ESXi Host (VM Source) | VMotion Communication on VMKernel Interface |
ESXi 3.x | 8000 | TCP | ESX/ESXi Host (VM Source) | ESX/ESXi Host (VM Target) | VMotion Communication on VMKernel Interface |
ESXi 3.x | 8042 - 8045 | TCP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESXi 3.x | 27000 | TCP | ESX/ESXi Host | VMware License Server | ESX/ESXi 3.x Host to License Server communication |
ESXi 3.x | 27010 | TCP | ESX/ESXi Host | VMware License Server | ESX/ESXi 3.x Host to License Server communication |
ESXi 4.x | 53 | UDP | ESX/ESXi Host | DNS Server | DNS |
ESXi 4.x | 80 | TCP | Client PC | ESX/ESXi Host | Redirect Web Browser to HTTPS Service (443) |
ESXi 4.x | 111 | TCP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESXi 4.x | 111 | UDP | ESX/ESXi Host | NFS Server | NFS Client – RPC Portmapper |
ESXi 4.x | 123 | UDP | ESX/ESXi Host | NTP Time Server | NTP Client |
ESXi 4.x | 161 | UDP | SNMP Server | ESXi 4.x Host | SNMP Polling. Not used in ESXi 3.x |
ESXi 4.x | 162 | UDP | ESX Host | SNMP Collector | SNMP Trap Send |
ESXi 4.x | 427 | UDP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESXi 4.x | 427 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Service Location Protocol (SLP) |
ESXi 4.x | 443 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi Host management connection |
ESXi 4.x | 443 | TCP | ESX/ESXi Host | ESX/ESXi Host | Host to host VM migration and provisioning |
ESXi 4.x | 514 | UDP | ESX/ESXi Host | Syslog Server | Remote syslog logging |
ESXi 4.x | 902 | TCP | VI/vSphere Client | ESX/ESXi Host | VI/vSphere Client to ESX/ESXi hosted VM connectivity |
ESXi 4.x | 902 | TCP/UDP | ESX/ESXi Host | ESX/ESXi Host | Authentication, Provisioning, VM Migration |
ESXi 4.x | 902 | TCP/UDP | ESX/ESXi Host | vCenter 4 Server | Heartbeat |
ESXi 4.x | 903 | TCP | VI/vSphere Client | ESX/ESXi Host | VM Remote VM Console |
ESXi 4.x | 2049 | TCP | ESX/ESXi Host | NFS Server | NFS Client |
ESXi 4.x | 2049 | UDP | ESX/ESXi Host | NFS Server | NFS Client |
ESXi 4.x | 2050 - 2250 | UDP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESXi 4.x | 3260 | TCP | ESX/ESXi Host | iSCSI SAN | Software iSCSI Client and Hardware iSCSI HBA |
ESXi 4.x | 5900 - 5964 | TCP | ESX/ESXi Host | ESX/ESXi Host | RFB Protocol used by management tools such as VNC |
ESXi 4.x | 5988 | TCP | ESX/ESXi Host | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESXi 4.x | 5989 | TCP | VirtualCenter/vCenter | ESX/ESXi Host | CIM Client to CIM Secure Server |
ESXi 4.x | 5989 | TCP | ESX/ESXi Host | VirtualCenter/vCenter | CIM Secure Server to CIM Client |
ESXi 4.x | 8000 | TCP | ESX/ESXi Host (VM Target) | ESX/ESXi Host (VM Source) | VMotion Communication on VMkernel Interface |
ESXi 4.x | 8000 | TCP | ESX/ESXi Host (VM Source) | ESX/ESXi Host (VM Target) | VMotion Communication on VMkernel Interface |
ESXi 4.x | 47 | UDP | ESX/ESXi Host | Physical Switches | vDS (Virtual Distributed Switch) Broadcast |
ESXi 4.x | 8042 - 8045 | TCP | ESX/ESXi Host | ESX/ESXi Host | VMware HA |
ESXi 4.x | 8100 | TCP/UDP | ESX/ESXi 4 Host | ESX/ESXi 4.x Host | VMware Fault Tolerance. ESX/ESXi 4 only. |
ESXi 4.x | 8200 | TCP/UDP | ESX/ESXi 4 Host | ESX/ESXi 4.x Host | VMware Fault Tolerance. ESX/ESXi 4 only. |
Heartbeat
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Heartbeat | 52267 | TCP | vCenter Server Heartbeat Console | vCenter Server Heartbeat Server | Client Connection Port |
Heartbeat | 57348 | TCP | vCenter Server Primary Server | vCenter Server Secondary Server | Default Channel Port to communicate between Primary and Secondary server |
Guided Consolidation
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Guided Consolidation | 135 | TCP/UDP | Consolidation Target (Physical Server) | vCenter Converter Server | Microsoft DCE Locator Service, also known at End-Point Mapper |
Guided Consolidation | 137 | TCP/UDP | Consolidation Target (Physical Server) | vCenter Converter Server | NetBIOS names service. Firewall administrators frequently see largernumbers of incoming packets to port 137. This is because of Windows servers that use NetBIOS (as well as DNS) to resolve IP addresses to names using the gethostbyaddr() function. As users behind the firewalls visit Windows-based Web sites, those servers frequently respond with NetBIOS lookups. |
Guided Consolidation | 138 | TCP/UDP | Consolidation Target (Physical Server) | vCenter Converter Server | NetBIOS datagram Used by Windows, as well as UNIX services (such as SAMBA). Port 138 is used primarily by the SMB browser service that obtains Network Neighborhood information. |
Guided Consolidation | 139 | TCP/UDP | Consolidation Target (Physical Server) | vCenter Converter Server | NetBIOS Session Windows File and Printer sharing. |
Guided Consolidation | 445 | TCP/UDP | Consolidation Target (Physical Server) | vCenter Converter Server | DNS Direct Hosting port. In Windows 2000 and Windows XP, redirector and server components now support direct hosting for communicating with other computers running Windows 2000 or Windows XP. Direct hosting does not use NetBIOS for name resolution. DNS is used for name resolution, and the Microsoft networking communication is sent directly over TCP without a NetBIOS header. Direct hosting over TCP/IP uses TCP and UDP port 445 instead of the NetBIOS session TCP port 139. |
Lab Manager
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Lab Manager | 137 | UDP | ESX/ESXi Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x |
Lab Manager | 138 | UDP | ESX/ESXi Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x |
Lab Manager | 139 | TCP | ESX/ESXi Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x |
Lab Manager | 389 | TCP | Lab Manager Server | LDAP Server | LDAP Authentication (optional) |
Lab Manager | 443 | TCP | Client PC | Lab Manager Server | Lab Manager Console (Web Browser) |
Lab Manager | 443 | TCP | Lab Manager Server | vCenter Server | Lab Manager to vCenter Server Communication |
Lab Manager | 445 | TCP | ESX/ESXi Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs. ESXi requires Lab Manager 4.x |
Lab Manager | 514 | TCP | Lab Manager Server | Virtual Router | Update IP tables and routing on the vRouter |
Lab Manager | 636 | TCP | Lab Manager Server | LDAP Server | LDAPS Authentication (optional) |
Lab Manager | 1433 | TCP | Lab Manager Server | Microsoft SQL Server | Lab Manager Connectivity to Microsoft SQL Server (for LM database) |
Lab Manager | 5212 | TCP | Lab Manager Server | ESX/ESXi Host | Lab Manager Agent. ESXi requires Lab Manager 4.x |
Orchestrator
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Orchestrator | 25 | TCP | VCO Server | SMTP Server | Email notifications |
Orchestrator | 389 | TCP | VCO Server | LDAP Server | LDAP Authentication |
Orchestrator | 443 | TCP | VCO Server | vCenter Server | Used to obtain virtual infrastructure and virtual machine information from orcestrated vCenter Server(s) through the vCenter API |
Orchestrator | 636 | TCP | VCO Server | LDAP Server | VCO uses LDAP authentication and group membership to determine role authorization in LCM and access to VMs/requests. This is the SSL secured LDAP protocol ldaps (the SSL pendent of 389). This is used for secured LDAP authentication |
Orchestrator | 1433 | TCP | VCO Server | Microsoft SQL Server | vCenter Orchestrator Server to Microsoft SQL Server for VCO Database |
Orchestrator | 1521 | TCP | VCO Server | Oracle Database Server | vCenter Orchestrator Server to Oracle for VCO Database |
Orchestrator | 3306 | TCP | VCO Server | MySQL Server | vCenter Orchestrator Server to MySQL Server for VCO Database |
Orchestrator | 5432 | TCP | VCO Server | PostgresSQL Server | vCenter Orchestrator Server to PortgresSQL Server for VCO Database |
Orchestrator | 8230 | TCP | VCO Client | VCO Server | Lookup port – The main port to communicate with Orchestrator Configurator server (JNDI port). All other ports communicate with the Orchestrator Configurator smart client through this one. It is part of the JBoss Application server infrastructure |
Orchestrator | 8240 | TCP | VCO Client | VCO Server | Command port – The application communication port (RMI container port), it is used for remote invocations. It is part of the JBoss Application server infrastructure. |
Orchestrator | 8244 | TCP | VCO Client | VCO Server | Data port used to access all Orchestrator data models,such as workflows and policies. It is part of the JBossapplication server infrastructure. |
Orchestrator | 8250 | TCP | VCO Client | VCO Server | Messaging port – The Java messaging port used to dispatch events. It is part of the JBoss Application server infrastructure |
Orchestrator | 8280 | TCP | VCO Server | VCO Server | Port used by VCO Server to connect to the Web front-end via HTTP |
Orchestrator | 8281 | TCP | VCO Server | VCO Server | Port used by VCO Server to connect to the Web front-end via HTTPS |
Orchestrator | 8281 | TCP | vCenter Server | VCO Server | Port used by VCO Server to connect to vCenter Server to communicate with the vCenter API |
Orchestrator | 8282 | TCP | VCO Client PC | VCO Server | HTTP server port – The port for the HTTP connector used to connect to the Web frontend. |
Orchestrator | 8283 | TCP | VCO Client PC | VCO Server | HTTPS server port – The port for the SSL HTTP connector used to connect to the Web frontend. Requires Jetty to be configured for SSL. |
Site Recovery Manager
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Site Recovery Manager | 80 | 80 | Site Recovery Manager | Remote vCenter Server | SRM communication. SRM Server at Site A to vCenter Server at Site B (failover) over HTTP and SSL tunnel |
Site Recovery | 80 | 80 | Site Recovery | Remote vCenter | SRM communication with local |
Manager | Manager | Server | vCenter server (inventory) & vSphere Client Plug-in download | ||
Site Recovery Manager | 443 | TCP | Site Recovery Manager | Remote vCenter Server | SRM communication with remote vCenter Server via HTTP over SSL tunnel |
Site Recovery Manager | 1433 | TCP | Site Recovery Manager | Microsoft SQL Server | SRM Connectivity to Microsoft SQL Server (for SRM database) |
Site Recovery Manager | 1521 | TCP | Site Recovery Manager | Oracle Database Server | SRM Connectivity to Oracle (for SRM database) |
Site Recovery | 1526 | TCP | Site Recovery Manager | Oracle Database | SRM Connectivity to Oracle (for |
Manager | Server | SRM database) | |||
Site Recovery Manager | 5000 | TCP | Site Recovery Manager | IBM DB2 Database Server | SRM Connectivity to IBM DB/2 (for SRM database) |
Site Recovery Manager | 8095 | TCP | Site Recovery Manager | vCenter server | SRM server and vCenter server (intrasite only). |
Site Recovery Manager | 8096 | TCP | Site Recovery Manager | vCenter server | vCenter server (for plug-in download). |
Site Recovery Manager | 9007 | TCP | Site Recovery Manager | External SRM API Client | SRM communication via WSDL |
Site Recovery Manager | 9008 | TCP | Site Recovery Manager | External SRM API Client | SRM communication via HTTP |
Stage Manager
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Stage Manager | 137 | UDP | ESX Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs |
Stage Manager | 138 | UDP | ESX Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs |
Stage Manager | 139 | TCP | ESX Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs |
Stage Manager | 389 | TCP | Stage Manager Server | LDAP Server | LDAP Authentication (optional) |
Stage Manager | 443 | TCP | Client PC | Stage Manager Server | Stage Manager Console (Web Browser) |
Stage Manager | 443 | TCP | Stage Manager Server | ESX Host | Stage Manager Server communication with ESX Host Agent |
Stage Manager | 443 | TCP | Stage Manager Server | vCenter Server | Stage Manager Server communucation with vCenter Server |
Stage Manager | 445 | TCP | ESX Host | SMB File Server | SMB File Sharing for Importing/Exporting VMs |
Stage Manager | 514 | TCP | Stage Manager Server | ESX Host | ESX Host Virtual Router |
Stage Manager | 636 | TCP | Stage Manager Server | LDAP Server | LDAPS Authentication (optional) |
Stage Manager | 5212 | TCP | Stage Manager Server | ESX Host | Stage Manager Agent |
Update Manager
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
Update Manager | 80 | TCP | Update Manager Server | www.vmware.com and | To obtain metadata for the updates, Update Manager must be able to connect to http://www.vmware.com |
Update Manager | 80 | TCP | ESX/ESXi Host | Update Manager Host | ESX/ESXi Host to Update Manager Server . The reverse proxy forwards the required to port 9084 |
Update Manager | 80 | TCP | Update Manager Server | vCenter Server | Update Manager to vCenter Server communication |
Update Manager | 443 | TCP | Update Manager Server | www.vmware.com and | To obtain metadata for the updates, Update Manager must be able to connect to http://www.vmware.com |
Update Manager | 443 | TCP | ESX/ESXi Host | Update Manager Server | ESX/ESXi Host to Update Manager Server . The reverse proxy forwards the required to port 9084 |
Update Manager | 443 | TCP | vCenter Server | Update Manager Server | vCenter Server to Update Manager Server. The reverse proxy forwards the request to port 8084 |
Update Manager | 902 | TCP | Update Manager Server | ESX/ESXi Host | To push patches and updates from Update Manager to the ESX/ESXi Hosts to be updated |
Update Manager | 1433 | TCP | Update Manager Server | Microsoft SQL Server | Update Manager to Microsoft SQL Server connectivity (for UM Database) |
Update Manager | 1521 | TCP | Update Manager Server | Oracle Database Server | Update Manager to Oracle connectivity (for UM Database) |
Update Manager | 8084 | TCP | Update Manager Server | vCenter Server | SOAP between components of Update Manager Server and the vCenter Update Manager client plug-in. Configurable at install. |
Update Manager | 9084 | TCP | ESX/ESXi host | Update Manager Server | ESX/ESXi hosts connect to the VUM webserver listening for updates. Configurable at install. |
Update Manager | 9087 | TCP | Update Manager Server | vCenter Server | Port used for uploading host update files. Configurable at install. |
Update Manager | 9000 - 9100 | TCP | ESX/ESXi Host | Update Manager Server | This is the recommend port range from which to choose ports for Update Manager if ports 80 and 443 are already in use. Update Manager automatically opens these ports for ESX Host scanning and remediation. |
vCenter
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
vCenter 2.5.x | 25 | TCP | vCenter Server | SMTP Server | Email notifications |
vCenter 2.5.x | 53 | UDP | vCenter Server | DNS Server | DNS lookups |
vCenter 2.5.x | 80 | TCP | Client PC | vCenter Server | Redirect Web Browser to HTTPS Service (443) |
vCenter 2.5.x | 88 | TCP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 2.5.x | 88 | UDP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 2.5.x | 161 | UDP | SNMP Server | vCenter Server | SNMP Polling |
vCenter 2.5.x | 162 | UDP | vCenter Server | SNMP Server | SNMP Trap Send |
vCenter 2.5.x | 389 | TCP | vCenter Server | LDAP Server | LDAP Authentication |
vCenter 2.5.x | 443 | TCP | vCenter Server | ESX/ESXi Host | vCenter Agent |
vCenter 2.5.x | 443 | TCP | Client PC | vCenter Server | VI Web Access (Web Browser) |
vCenter 2.5.x | 443 | TCP | VI/vSphere Client | vCenter Server | VI/vSphere Client access to vCenter Server |
vCenter 2.5.x | 445 | TCP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 2.5.x | 445 | UDP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 2.5.x | 902 | TCP/UDP | vCenter Server | ESX/ESXi Host | Heartbeat |
vCenter 2.5.x | 902 | TCP/UDP | ESX/ESXi Host | vCenter Server | Heartbeat |
vCenter 2.5.x | 903 | TCP | Client PC | vCenter Server | VI/vSphere Client to VM Console |
vCenter 2.5.x | 903 | TCP | vCenter Server | ESX/ESXi Host | VI/vSphere Client to VM Console (after connection established between VI/vSphere Client and vCenter) |
vCenter 2.5.x | 1433 | TCP | vCenter Server | Microsoft SQL Server | For vCenter Microsoft SQL Server Database |
vCenter 2.5.x | 1521 | TCP | vCenter Server | Oracle Database Server | For vCenter Oracle Database |
vCenter 2.5.x | 5989 | TCP | VirtualCenter/vCenter | ESX/ESXi Host | vCenter to ESX |
vCenter 2.5.x | 5989 | TCP | ESX/ESXi Host | VirtualCenter/vCenter | ESX to vCenter |
vCenter 2.5.x | 8005 | TCP | vCenter Server | vCenter Server | Internal Communication Port |
vCenter 2.5.x | 8006 | TCP | vCenter Server | vCenter Server | Internal Communication Port |
vCenter 2.5.x | 8083 | TCP | vCenter Server | vCenter Server | Internal Service Diagnostics |
vCenter 2.5.x | 8085 | TCP | vCenter Server | vCenter Server | Internal Service Diagnostics |
vCenter 2.5.x | 8086 | TCP | vCenter Server | vCenter Server | Internal Communication Port |
vCenter 2.5.x | 8087 | TCP | vCenter Server | vCenter Server | Internal Service Diagnostics |
vCenter 2.5.x | 27000 | TCP | vCenter Server | VMware License Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 2.5.x | 27000 | TCP | VMware License Server | vCenter Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 2.5.x | 27010 | TCP | vCenter Server | VMware License Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 2.5.x | 27010 | TCP | VMware License Server | vCenter Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 4.x | 25 | TCP | vCenter Server | SMTP Server | Email notifications |
vCenter 4.x | 53 | UDP | vCenter Server | DNS Server | DNS lookups |
vCenter 4.x | 80 | TCP | Client PC | vCenter Server | Redirect Web Browser to HTTPS Service (443) |
vCenter 4.x | 80 | TCP | vCenter Server | ESX/ESXi 4.x | DPM with IPMI (iLO/BMC) ASF Remote Management and Control Protocol |
vCenter 4.x | 88 | UDP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 4.x | 88 | TCP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 4.x | 161 | UDP | SNMP Server | vCenter Server | SNMP Polling |
vCenter 4.x | 162 | UDP | vCenter Server | SNMP Server | SNMP Trap Send |
vCenter 4.x | 389 | TCP | vCenter Server | Linked vCenter Servers | Bi-directional LDAP authentication with Kerberos encryption on TCP port 389 is required between all vCenters that need to replicate. |
vCenter 4.x | 443 | TCP | vCenter Server | ESX/ESXi Host | vCenter Agent |
vCenter 4.x | 443 | TCP | vCenter Server | ESX/ESXi 4.x | Host DPM with HP iLO Remote Management and Control Protocol |
vCenter 4.x | 443 | TCP | Client PC | vCenter Server | VI Web Access (Web Browser) |
vCenter 4.x | 443 | TCP | VI/vSphere Client | vCenter Server | VI\vSphere Client access to vCenter Server |
vCenter 4.x | 445 | TCP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 4.x | 445 | UDP | vCenter Server | Active Directory Server | AD Authentication |
vCenter 4.x | 623 | UDP | vCenter Server | ESX/ESXi 4.x Host | DPM with IPMI (iLO/BMC) ASF Remote Management and Control Protocol |
vCenter 4.x | 636 | TCP | vCenter Server | Linked vCenter Servers | Linked mode connectivity between vCenter Servers |
vCenter 4.x | 902 | TCP/UDP | vCenter Server | ESX/ESXi Host | Heartbeat |
vCenter 4.x | 902 | TCP/UDP | ESX/ESXi Host | vCenter Server | Heartbeat |
vCenter 4.x | 903 | TCP | Client PC | vCenter Server | VI/vSphere Client to VM Console |
vCenter 4.x | 903 | TCP | vCenter Server | ESX/ESXi Host | VI/vSphere Client to VM Console (after connection established between VI/vSphere Client and vCenter) |
vCenter 4.x | > 1024 (dynamic) | RPC | Linked vCenter Servers | Linked vCenter Servers | Bi-directional RPC communication on dynamic TCP ports is required between all vCenters that need to replicate (via ADAM). A VIC still needs the a direct connection to all vCenters that own an object it needs to manage. |
vCenter 4.x | 1433 | TCP | vCenter Server | Microsoft SQL Server | For vCenter Microsoft SQL Server Database |
vCenter 4.x | 1521 | TCP | vCenter Server | Oracle Database Server | For vCenter Oracle Database |
vCenter 4.x | 5989 | TCP | VirtualCenter/vCenter | ESX/ESXi Host | vCenter to ESX |
vCenter 4.x | 5989 | TCP | ESX/ESXi Host | VirtualCenter/vCenter | ESX to vCenter |
vCenter 4.x | 8005 | TCP | vCenter Server | vCenter Server | Internal Communication Port |
vCenter 4.x | 8006 | TCP | vCenter Server | vCenter Server | Internal Communication Port |
vCenter 4.x | 8080 | TCP | Client PC | vCenter 4 Server | VMware vCenter 4 Management Web Services - HTTP |
vCenter 4.x | 8083 | TCP | vCenter Server | vCenter Server | Internal Service Diagnostics |
vCenter 4.x | 8085 | TCP | vCenter Server | vCenter Server | Internal Service Diagnostics |
vCenter 4.x | 8086 | TCP | vCenter Server | vCenter Server | Internal Communication Port |
vCenter 4.x | 8087 | TCP | vCenter Server | vCenter Server | Internal Service Diagnostics |
vCenter 4.x | 8443 | TCP | Client PC | vCenter 4 Server | VMware vCenter 4 Management Web Services - HTTPS |
vCenter 4.x | 27000 | TCP | vCenter Server | VMware License Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 4.x | 27000 | TCP | VMware License Server | vCenter Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 4.x | 27010 | TCP | vCenter Server | VMware License Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 4.x | 27010 | TCP | VMware License Server | vCenter Server | Licensing via FlexLM. Only required by vCenter 4 if ESX/ESXi 3.x Hosts will be supported |
vCenter 4.1 | 60099 | TCP | vCenter Server | vCenter 4 Server Services | This port is for internal communication between vCenter Server and its solutions. Specifically, it is used to exchange messages about inventory. If you do not have it open, a solution that integrates with vCenter Server using this service may be affected. |
vCenter Operations
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
vCenter Operations Standard 1.x | 22 | vCenter 4.1 | vCenter Operations Standard | Virtual appliance | Must be open to enable SSH access to the vCenter Operations Stand virtual appliance |
vCenter Operations Standard 1.x | 443 | vCenter 4.1 | vCenter Operations Standard | Virtual appliance | HTTPS server port for the vCenter Operations Standard Administration page |
vCenter Operations Standard 1.x | 5480 | vCenter 4.1 | vCenter Operations Standard | Virtual appliance | HTTPS server port for the VMware Studio Web console to administer the virtual appliance |
View
Product | Port | Protocol | Source | Target | Purpose |
---|---|---|---|---|---|
View 3.x | 3389 | TCP | Thin Client | ESX host | RDP Protocol |
View 3.x | 18443 | TCP | View Connection Server/View Manager | vCenter Server | View Composer |
View 3.x | 32111 | TCP | View Agent (Virtual Desktop) | View Client | USB Device Communication |
View 3.x | 32111 | TCP | View Client | View Agent (Virtual Desktop) | USB Device Communication |
View 4.x | 902 | TCP | View Client/View Client with Offline Desktop | ESX Host | (Optional) View Client with Offline Desktop data is downloaded and uploaded through this port. |
View 4.x | 3268 | TCP | View/VDM Connection Server/View Manager | Active Directory Server | Global Catalog Server |
View 4.x | 3269 | TCP | View/VDM Connection Server/View Manager | Active Directory Server | Global Catalog Server |
View 4.x | 3389 | TCP | Thin Client | ESX host | RDP Protocol |
View 4.x | 9427 | TCP | View Client/View Client with Offline Desktop | View Agent (Virtual Desktop) | (Optional) Multimedia Redirection (MMR). MMR is support by View Client and View Client with Offline Desktop on certain operating systems. |
View 4.x | 18443 | TCP | View Connection Server/View Manager | vCenter Server | View Composer |
View 4.0.x | 50002 | TCP/UDP | View Agent (Virtual Desktop) | View Client | PCoIP (AES 128-bit encryption) |
View 4.0.x | 50002 | TCP/UDP | View Client | View Agent (Virtual Desktop) | PCoIP (AES 128-bit encryption) |
View 4.5.x | 80/443 | TCP | View Client with Local Mode | View Transfer Server | http(s) access via direct connection for downloading and uploading Local Mode data |
View 4.5.x | 80/443 | TCP | Security Server | View Transfer Server | http(s) access via tunnel connection for downloading and uploading Local Mode data |
View 4.5.x | 902 | TCP | View Connection Server | ESX Host | Used when checking out local desktops. If you intend to use View Client with Local Mode, port 902 must be accessible on your ESX host |
View 4.5.x | 902 | TCP | View Transfer Server | ESX Host | Publishing View Composer packages for Local Mode |
View 4.5.x | 4001 | TCP | View Connection Server | View Transfer Server | Required by JMS for Local Mode |
View 4.5.x | 4172 | TCP/UDP | View Agent (Virtual Desktop) | View Client | PCoIP (AES 128-bit encryption) |
View 4.5.x | 4172 | TCP/UDP | View Client | View Agent (Virtual Desktop) | PCoIP (AES 128-bit encryption) |
View 4.6.x | 80/443 | TCP | View Client with Local Mode | View Transfer Server | http(s) access via direct connection for downloading and uploading Local Mode data |
View 4.6.x | 80/443 | TCP | Security Server | View Transfer Server | http(s) access via direct connection for downloading and uploading Local Mode data |
View 4.6.x | 902 | TCP | View Connection Server | ESX Host | Used when checking out local desktops. If you intend to use View Client with Local Mode, port 902 must be accessible on your ESX host |
View 4.6.x | 902 | TCP | View Transfer Server | ESX Host | Publishing View Composer packages for Local Mode |
View 4.6.x | 4001 | TCP | View Connection Server | View Transfer Server | Required by JMS for Local Mode |
View 4.6.x | 4172 | TCP/UDP | View Agent (Virtual Desktop) | View Client | PCoIP (AES 128-bit encryption) |
View 4.6.x | 4172 | TCP/UDP | View Client | View Agent (Virtual Desktop) | PCoIP (AES 128-bit encryption) |
View/VDM 2.x | 80 | TCP | View/VDM Client | View/VDM Security Server | VDM Access (not required if only HTTPS is to be supported) |
View/VDM 2.x | 80 | TCP | Client PC | View/VDM Security Server | VDM Web Access (not required if only HTTPS is to be supported) The Security Server used as a proxy in a DMZ to allow for external connections in. The View Manager/Connection Broker has an ADAM instance on it and thus, a fair amount of the AD (not a good thing to put on the DMZ). If View is LAN-based only, then it’s irrelevant. If it’s publicly accessed, then you definitely want a Security Server to act on behalf of external clients coming in (assuming no VPN) |
View/VDM 2.x | 80 | TCP | View/VDM Client | View/VDM Connection Server | VDM Access (not required if only HTTPS is to be supported) |
View/VDM 2.x | 80 | TCP | Client PC | View/VDM Connection Server | VDM Web Access (not required if only HTTPS is to be supported) |
View/VDM 2.x | 88 | UDP | View/VDM Connection Server/View Manager | Active Directory Server | AD Authentication |
View/VDM 2.x | 88 | TCP | View/VDM Connection Server/View Manager | Active Directory Server | AD Authentication |
View/VDM 2.x | 389 | TCP/UDP | View/VDM Connection Server/View Manager | LDAP Server | LDAP Authentication |
View/VDM 2.x | 443 | TCP | View/VDM Client | View/VDM Security Server | VDM Access |
View/VDM 2.x | 443 | TCP | Client PC | View/VDM Connection Server/View Manager | VDM Web Access and VDM Administration |
View/VDM 2.x | 443 | TCP | Thin Client | View/VDM Connection Server/View Manager | VDM API |
View/VDM 2.x | 443 | TCP | View/VDM Client | View/VDM Connection Server/View Manager | VDM Access |
View/VDM 2.x | 443 | TCP | Client PC | View/VDM Security Server | VDM Web Access (Web Browser) |
View/VDM 2.x | 443 | TCP | View/VDM Connection Server/View Manager | vCenter Server | VDM to vCenter communication |
View/VDM 2.x | 445 | UDP | View/VDM Connection Server/View Manager | Active Directory Server | AD Authentication |
View/VDM 2.x | 445 | TCP | View/VDM Connection Server/View Manager | Active Directory Server | AD Authentication |
View/VDM 2.x | 1024 - 65535 | TCP | View/VDM Connection Server/View Manager | Virtual Desktop VM (View/VDM Agent) | Ephemeral Ports. A short-lived connection between View Manager and the virtual desktop |
View/VDM 2.x | 1024 - 65535 | TCP | View/VDM Connection Server/View Manager | View/VDM Connection Server/View Manager | This is required for ADAM replication (Active Directory «lite» replication) between VDM Connection Servers. With a Registry entry this can be fixed to a defined set of ports, but by default its a random TCP high port |
View/VDM 2.x | 3389 | TCP | View/VDM Security Server | Virtual Desktop VM (View/VDM Agent) | Tunneled RDP Connection (RSA RC4 encryption, can be set High/Medium/Low) - High: encrypts both the data sent from client to server and the data sent from server to client using a 128 bit key. - Medium: encrypts both the data sent from client to server and the data sent from server to client using a 56 bit key if the client is a Windows 2000 or above client, or a 40 bit key if the client is an earlier version. - Low: encrypts only the data sent from client to server, using either a 56 or 40 bit key, depending on the client version. Useful to protect usernames and passwords sent from client to server. |
View/VDM 2.x | 3389 | TCP | Client PC/Thin Client/View/VDM Client | Virtual Desktop VM (View/VDM Agent) | Direct RDP Connection (RSA RC4 encryption, can be set High/Medium/Low) - High: encrypts both the data sent from client to server and the data sent from server to client using a 128 bit key. - Medium: encrypts both the data sent from client to server and the data sent from server to client using a 56 bit key if the client is a Windows 2000 or above client, or a 40 bit key if the client is an earlier version. - Low: encrypts only the data sent from client to server, using either a 56 or 40 bit key, depending on the client version. Useful to protect usernames and passwords sent from client to server. |
View/VDM 2.x | 4001 | TCP | View/VDM Security Server | View/VDM Connection Server/View Manager | Java Messenger Service (JMS) |
View/VDM 2.x | 4001 | TCP | View/VDM Connection Server/View Manager | View/VDM Security Server | Java Messenger Service (JMS) |
View/VDM 2.x | 4001 | TCP | Virtual Desktop VM (View/VDM Agent) | View/VDM Connection Server/View Manager | |
View/VDM 2.x | 4100 | TCP | View/VDM Connection Server/View Manager | View/VDM Connection Server/View Manager | Java Messenger Service (JMS) inter-router traffic |
View/VDM 2.x | 8009 | TCP | View/VDM Security Server | View/VDM Connection Server/View Manager | Apache Jserv Protocol (AJP) |
View/VDM 2.x | 8009 | TCP | View/VDM Connection Server/View Manager | View/VDM Security Server | Apache Jserv Protocol (AJP) |
View/VDM 2.x | 42966 | TCP | View Client/View Client with Offline Desktop | ESX Host | (Optional) Hewlett-Packard RGS Sender Application is the server-side component of the HP RGS remote display protocol |
vSphere Management Assistant | 44 | TCP | vSphere Management Assistant | vSphere Management Assistant | For SDK traffic |