Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
vsp_41_esx_server_config.pdf
Скачиваний:
10
Добавлен:
06.02.2016
Размер:
2.67 Mб
Скачать

Chapter 12 Securing an ESX Configuration

5Select the service to configure, and click Options.

The Startup Policy dialog box determines when the service starts. This dialog box also provides information about the current state of the service and provides an interface for manually starting, stopping, or restarting the service.

6 Select a policy from the Startup Policy list.

7Click OK.

TCP and UDP Ports for Management Access

vCenter Server, ESX hosts, and other network components are accessed using predetermined TCP and UDP ports. If you manage network components from outside a firewall, you might be required to reconfigure the firewall to allow access on the appropriate ports.

Table 12-1 lists TCP and UDP ports, and the purpose and the type of each.

The ports are connected through the service console interface, unless otherwise indicated.

Table 12-1. TCP and UDP Ports

Port

Purpose

Traffic Type

 

 

 

22

SSH Server

Incoming TCP

 

 

 

80

HTTP access

Incoming TCP

 

The default non-secure TCP Web port typically used in conjunction with port 443

 

 

as a front end for access to ESX networks from the Web. Port 80 redirects traffic

 

 

to an HTTPS landing page (port 443).

 

 

Connection to vSphere Web Access from the Web

 

 

WS-Management

 

 

 

 

123

NTP Client

Outgoing UDP

 

 

 

427

The CIM client uses the Service Location Protocol, version 2 (SLPv2) to find CIM

Incoming and

 

servers.

outgoing UDP

 

 

 

443

HTTPS access

Incoming TCP

 

vCenter Server access to ESX hosts

 

 

Default SSL Web port

 

 

vSphere Client access to vCenter Server

 

 

vSphere Client access to ESX hosts

 

 

WS-Management

 

 

vSphere Client access to vSphere Update Manager

 

 

vSphere Converter access to vCenter Server

 

 

vSphere Web Access and third-party network management client connections to

 

 

vCenter Server

 

 

Direct vSphere Web Access and third-party network management clients access

 

 

to hosts

 

 

 

 

902

Host access to other hosts for migration and provisioning

Incoming TCP,

 

Authentication traffic for ESX (xinetd/vmware-authd)

outgoing UDP

 

vSphere Client access to virtual machine consoles

 

 

(UDP) Status update (heartbeat) connection from ESX to vCenter Server

 

 

 

 

903

Remote console traffic generated by user access to virtual machines on a specific

Incoming TCP

 

ESX host.

 

 

vSphere Client access to virtual machine consoles

 

 

vSphere Web Access Client access to virtual machine consoles

 

 

MKS transactions (xinetd/vmware-authd-mks)

 

 

 

 

2049

Transactions from NFS storage devices

Incoming and

 

This port is used on the VMkernel interface rather than the service console

outgoing TCP

 

interface.

 

 

 

 

VMware, Inc.

159

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]