Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
vsp_41_esx_server_config.pdf
Скачиваний:
10
Добавлен:
06.02.2016
Размер:
2.67 Mб
Скачать

ESX Configuration Guide

Figure 12-3. Port Use for vSphere Client Communications with ESX vSphere Client

virtual machine management functions

virtual machine console

 

 

Port 443

 

firewall

 

Port 903

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

ESX

 

 

 

 

 

 

 

 

 

service console

 

VMkernel

 

 

 

 

vmware-hostd

 

virtual machine

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

vmware-authd

 

vmkauthd

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

If you have a firewall between your vCenter Server system and vCenter Server managed host, open Ports 443 and 903 in the firewall to allow data transfer to ESX hosts from vCenter Server and ESX hosts directly from the vSphere Client and vSphere Web Access.

For additional information on configuring the ports, see the firewall system administrator.

Connecting ESX Hosts Through Firewalls

If you have a firewall between two ESX hosts and you want to allow transactions between the hosts or use vCenter Server to perform any source or target activities, such as VMware High Availability (HA) traffic, migration, cloning, or vMotion, you must configure a connection through which the managed hosts can receive data.

To configure a connection for receiving data, open ports in the following ranges:

n443 (server-to-server migration and provisioning traffic)

n2050–2250 (for HA traffic)

n8000 (for vMotion)

n8042–8045 (for HA traffic)

Refer to the firewall system administrator for additional information on configuring the ports.

Configuring Firewall Ports for Supported Services and Management Agents

You must configure firewalls in your environment to accept commonly supported services.

Use the vSphere Client to configure the service console firewall. When you configure the ESX host security profile in vCenter Server, you add or remove these services or agents, automatically opening or closing predetermined ports in the firewall to allow communication with the service or agent.

The following services and agents are commonly present in a vSphere environment:

nNFS client (insecure service)

nNTP client

156

VMware, Inc.

Chapter 12 Securing an ESX Configuration

niSCSI software client

nCIM HTTP server (insecure service)

nCIM HTTPS server

nSyslog client

nNFS server (insecure service)

nNIS client

nSMB client (insecure service)

nFTP client (insecure service)

nSSH client

nTelnet client (insecure service)

nSSH server

nTelnet server (insecure service)

nFTP server (insecure service)

nSNMP server

nOther supported management agents that you install

NOTE This list can change, so you might find that the vSphere Client provides services and agents not mentioned in the list. Also, not all services on the list are installed by default. You might be required to perform additional tasks to configure and enable these services.

If you are installing a device, service, or agent not on this list, open ports in the service console firewall from a command line.

Allow Access to ESX for a Service or Management Agent

You can configure firewall properties to allow access for a service or management agent.

Procedure

1 Log in to a vCenter Server system using the vSphere Client.

2Select the host in the inventory panel.

3Click the Configuration tab and click Security Profile.

The vSphere Client displays a list of active incoming and outgoing connections with the corresponding firewall ports.

4Click Properties to open the Firewall Properties dialog box.

The Firewall Properties dialog box lists all the services and management agents that you can configure for the host.

5Select the services and agents to enable.

The Incoming Ports and Outgoing Ports columns indicate the ports that the vSphere Client opens for the service. The Protocol column indicates the protocol that the service uses. The Daemon column indicates the status of daemons associated with the service.

6Click OK.

VMware, Inc.

157

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]