VMware Ports and Protocols CheatSheet

VMware Ports & Protocols Cheatsheet | Master Firewall Matrix
41 Products & 3,000+ Ports

VMware Infrastructure Architecture & Firewall Guidelines

Enterprise network security requirements, overlay encapsulation & essential traffic flows
vCenter Server (VCSA) Core Services
Centralized vSphere management, VAMI, and Host communication
Key Ports: 443 (HTTPS), 5480 (VAMI), 902 (ESXi Heartbeat/NFC)
vCenter coordinates all compute resources. Admins access the vSphere Client via port 443. The appliance itself is configured through VAMI on 5480. vCenter communicates with managed ESXi hosts using UDP/TCP port 902 for agent heartbeats (vpxa/hostd) and provisioning.
ESXi Hypervisor Management & vMotion
Bare-metal compute, vMotion live migrations, and host monitoring
Key Ports: 443 (Host Client), 902 (MKS), 8000 (vMotion)
ESXi hosts run virtual workloads and management daemons. Direct web client access runs over 443. Port 902 handles remote console (MKS) streams. Live vMotion migrations occur across dedicated vmkernel interfaces on TCP port 8000.
VMware NSX-T Software-Defined Networking
Geneve overlay tunnels, CCP/LCP clustering, and routing
Key Ports: 6081 (Geneve UDP), 1234/1235 (CCP), 179 (BGP)
NSX-T powers micro-segmentation and virtual routing. Host and Edge Tunnel Endpoints (TEPs) encapsulate layer-2 frames into UDP 6081 (Geneve) with minimum MTU 1600. Control plane clustering utilizes ports 1234 and 1235. Dynamic routing peers via BGP on 179.
VMware vSAN Clustered Storage
Distributed object storage and cluster metadata directory
Key Ports: 12321 (CMDS), 23451 (Gossip/Heartbeat), 2233 (RDT)
vSAN aggregates local host NVMe/SSD storage into a distributed datastore. Inter-node directory synchronization (CMDS) occurs on port 12321. Cluster health and monitoring runs on 23451 and 2233. Native file services expose NFS (2049) and SMB (445).

This authoritative firewall cheat sheet lists the critical network ports required across core VMware infrastructure. All rules should be configured in datacenter firewalls, distributed firewalls (DFW), and network security groups (NSGs).

Table 1: Master Reference Matrix of Critical VMware Infrastructure Firewall Ports and Protocols
Port Proto VMware Product Source → Destination Service & Firewall Purpose
443 HTTPS vCenter / ESXi Administrator / Client → vCenter & ESXi vSphere Client HTTPS web access, SOAP/REST APIs, SDK integration, and single sign-on (SSO) authentication.
902 TCP / UDP VMware vSphere vCenter Server ↔ ESXi Hypervisors Agent heartbeat (vpxa to hostd), Network File Copy (NFC) disk provisioning, and direct VM Remote Console (MKS) sessions.
5480 HTTPS vCenter Appliance Web Browser → vCenter VAMI vCenter Server Appliance Management Interface (VAMI) for system updates, backup scheduling, and appliance networking.
8000 TCP VMware ESXi ESXi Host ↔ ESXi Host (VMkernel) vSphere vMotion live virtual machine memory and execution state migration across dedicated VMkernel interfaces.
6081 UDP VMware NSX Host TEP ↔ Edge TEP Geneve (Generic Network Virtualization Encapsulation) overlay tunnels for East-West and North-South virtual routing (MTU ≥ 1600 bytes).
12321 TCP VMware vSAN ESXi Host ↔ ESXi Host vSAN Cluster Monitoring, Directory and Membership Services (CMDS) metadata synchronization across cluster nodes.
23451 UDP VMware vSAN ESXi Host ↔ ESXi Host vSAN cluster heartbeat, node health detection, and inter-node gossip membership discovery.
2233 TCP VMware vSAN ESXi Host ↔ ESXi Host vSAN Reliable Datagram Transport (RDT) for distributed storage object reads, writes, and replica mirroring.
8443 TCP / UDP VMware Horizon Horizon Client → Unified Access Gateway Blast Extreme display protocol session data and BEAT (Blast Extreme Adaptive Transport) audio/video streaming.
4172 TCP / UDP VMware Horizon Horizon Client → Unified Access Gateway Teradici PCoIP display protocol session initiation (TCP) and display streaming traffic (UDP).
4500 UDP VMware HCX HCX Interconnect ↔ HCX Interconnect HCX WAN Interconnect IPsec transport tunnel for hybrid cloud and cross-datacenter live workload migrations.
9443 HTTPS HCX / UAG Administrator → HCX Manager / UAG Appliance management console, Service Mesh deployment, and Unified Access Gateway administrative configuration.
8095 TCP Site Recovery Mgr Protected Site SRM ↔ Recovery Site SRM Site Recovery Manager (SRM) service-to-service disaster recovery coordination and protection group orchestration.
9086 TCP vSphere Replication vCenter / SRM → Replication Appliance vSphere Replication management, protection policy application, and virtual machine replication scheduling.
6443 HTTPS Tanzu / TKG kubectl / Nodes → Kubernetes API Tanzu Kubernetes Grid (TKG) control plane API server access for cluster deployment and container management.
22 SSH Core vSphere Admin Workstation → ESXi / VCSA Secure Shell (SSH) remote command-line administration, direct host troubleshooting, and support log collection.
123 UDP All VMware All Appliances → NTP Server Network Time Protocol time synchronization (essential for Kerberos, SSL/TLS certificate validity, and HA clustering).
53 TCP / UDP All VMware All Appliances → DNS Server Domain Name System forward and reverse name resolution across all vSphere management components and clusters.

1. VMware vSphere & vCenter Server Firewall Port Requirements

VMware vSphere 8 and 7 rely on a well-defined set of firewall rules to ensure high availability, administrative access, and inter-host communication:

  • Port 443 (TCP - HTTPS): The primary entry point for the vSphere Client, VMware PowerCLI, REST APIs, and vSphere SDK. Internal microservices communicate with the VMware Identity Manager (vIDM) and Single Sign-On (SSO) over port 443.
  • Port 902 (TCP/UDP - Hostd/Heartbeat): Bidirectional communication between vCenter Server and the ESXi hostd daemon. vCenter sends UDP heartbeats to ESXi hosts on port 902; if blocked for more than 60 seconds, hosts show as "Not Responding". It also carries Network File Copy (NFC) traffic for ISO transfers and OVF deployments.
  • Port 5480 (TCP - VAMI): Dedicated port for the vCenter Server Appliance Management Interface (VAMI). Required for applying appliance patches, configuring network interfaces, monitoring CPU/RAM consumption, and executing file-based backups (FTP, FTPS, HTTP, HTTPS, SCP).
  • Port 8000 (TCP - vMotion): Dedicated live migration stream. ESXi hosts initiate direct TCP connections on port 8000 over dedicated vMotion VMkernel ports with jumbo frames (MTU 9000).

2. VMware NSX Software-Defined Networking & Geneve Encapsulation

VMware NSX (formerly NSX-T) creates software-defined overlay networks using Tunnel Endpoints (TEPs):

  • Port 6081 (UDP - Geneve): Geneve (Generic Network Virtualization Encapsulation) encapsulates layer-2 Ethernet frames into layer-3 UDP datagrams. Critical: Network underlay devices must allow UDP 6081 with a Minimum Transmission Unit (MTU) of at least 1600 bytes (1700 bytes strongly recommended) to avoid IP fragmentation.
  • Port 1234 & 1235 (TCP - CCP): Central Control Plane (CCP) clustering and communication between NSX Manager nodes and transport node Local Control Plane (LCP) daemons.
  • Port 179 (TCP - BGP): Border Gateway Protocol routing sessions between NSX Tier-0 Gateways and upstream physical Top-of-Rack (ToR) routers.

3. VMware vSAN & vSAN Express Storage Architecture (ESA)

VMware vSAN pools host NVMe/SSD storage into a resilient distributed object datastore:

  • Port 12321 (TCP - CMDS): Cluster Monitoring, Directory, and Membership Services (CMDS) handles cluster state changes, disk grouping, and quorum configuration.
  • Port 23451 (UDP - Gossip & Heartbeat): High-frequency cluster node heartbeats and health metrics gossip protocol.
  • Port 2233 (TCP - RDT): Reliable Datagram Transport ensures high-throughput, low-latency object read/write operations and mirroring.
  • Ports 2049 & 445 (TCP - File Services): Exposes vSAN Native File Services via NFS v3/v4.1 and SMB v2/v3 to enterprise file shares.

4. VMware Horizon & Unified Access Gateway (UAG) VDI Ports

Secure remote desktop and application access requires opening perimeter firewall ports to the Unified Access Gateway (UAG):

  • Port 443 (TCP - HTTPS): Initial client authentication, XML broker negotiation, HTML5 web access, and tunneled protocol sessions.
  • Port 8443 (TCP/UDP - Blast Extreme): High-performance Blast Extreme display protocol utilizing H.264/HEVC encoding and BEAT adaptive UDP transport for fluctuating bandwidth.
  • Port 4172 (TCP/UDP - PCoIP): Teradici PCoIP display protocol stream for legacy clients and zero clients.
  • Port 9427 & 32111 (TCP): Client Drive Redirection (CDR), Multimedia Redirection (MMR), and USB redirection when segregated from display protocols.

5. VMware HCX Cross-Cloud Migration & Hybrid Connectivity

VMware HCX abstracts on-premises and hyperscaler VMware Cloud (VMC on AWS, Azure VMware Solution, Google Cloud VMware Engine) resources:

  • Port 4500 (UDP - IPsec WAN Interconnect): Encrypted WAN transport tunnel connecting source and target HCX Interconnect (IX) appliances across the public internet or private DirectConnect/ExpressRoute circuits.
  • Port 9443 (TCP - HCX Manager): Web administration portal, fleet management, and site-pairing orchestration.
  • Port 8123 (TCP - Bulk Migration): Manages replication-assisted vMotion and non-disruptive cold/bulk workload data transfers.

Discussion 0

Author Active
Leave a Response
Verified Discussion Policy: Comments are moderated by the engineering team to ensure high-quality technical answers and zero spam.
Join the Discussion
Markdown supported: Use `command` for inline code
Theme Mode