VMware Ports & Protocols Cheatsheet
Complete port reference for the VMware portfolio — 41 products with 3,006 unique port entries sourced from official VMware documentation.
VMware Infrastructure Architecture & Firewall Guidelines
Core VMware Solutions Architecture
Master VMware Ports Quick Reference (Core Firewall Matrix)
This authoritative firewall cheat sheet lists the critical network ports required across core VMware infrastructure. All rules should be configured in datacenter firewalls, distributed firewalls (DFW), and network security groups (NSGs).
| Port | Proto | VMware Product | Source → Destination | Service & Firewall Purpose |
|---|---|---|---|---|
| 443 | HTTPS | vCenter / ESXi | Administrator / Client → vCenter & ESXi | vSphere Client HTTPS web access, SOAP/REST APIs, SDK integration, and single sign-on (SSO) authentication. |
| 902 | TCP / UDP | VMware vSphere | vCenter Server ↔ ESXi Hypervisors | Agent heartbeat (vpxa to hostd), Network File Copy (NFC) disk provisioning, and direct VM Remote Console (MKS) sessions. |
| 5480 | HTTPS | vCenter Appliance | Web Browser → vCenter VAMI | vCenter Server Appliance Management Interface (VAMI) for system updates, backup scheduling, and appliance networking. |
| 8000 | TCP | VMware ESXi | ESXi Host ↔ ESXi Host (VMkernel) | vSphere vMotion live virtual machine memory and execution state migration across dedicated VMkernel interfaces. |
| 6081 | UDP | VMware NSX | Host TEP ↔ Edge TEP | Geneve (Generic Network Virtualization Encapsulation) overlay tunnels for East-West and North-South virtual routing (MTU ≥ 1600 bytes). |
| 12321 | TCP | VMware vSAN | ESXi Host ↔ ESXi Host | vSAN Cluster Monitoring, Directory and Membership Services (CMDS) metadata synchronization across cluster nodes. |
| 23451 | UDP | VMware vSAN | ESXi Host ↔ ESXi Host | vSAN cluster heartbeat, node health detection, and inter-node gossip membership discovery. |
| 2233 | TCP | VMware vSAN | ESXi Host ↔ ESXi Host | vSAN Reliable Datagram Transport (RDT) for distributed storage object reads, writes, and replica mirroring. |
| 8443 | TCP / UDP | VMware Horizon | Horizon Client → Unified Access Gateway | Blast Extreme display protocol session data and BEAT (Blast Extreme Adaptive Transport) audio/video streaming. |
| 4172 | TCP / UDP | VMware Horizon | Horizon Client → Unified Access Gateway | Teradici PCoIP display protocol session initiation (TCP) and display streaming traffic (UDP). |
| 4500 | UDP | VMware HCX | HCX Interconnect ↔ HCX Interconnect | HCX WAN Interconnect IPsec transport tunnel for hybrid cloud and cross-datacenter live workload migrations. |
| 9443 | HTTPS | HCX / UAG | Administrator → HCX Manager / UAG | Appliance management console, Service Mesh deployment, and Unified Access Gateway administrative configuration. |
| 8095 | TCP | Site Recovery Mgr | Protected Site SRM ↔ Recovery Site SRM | Site Recovery Manager (SRM) service-to-service disaster recovery coordination and protection group orchestration. |
| 9086 | TCP | vSphere Replication | vCenter / SRM → Replication Appliance | vSphere Replication management, protection policy application, and virtual machine replication scheduling. |
| 6443 | HTTPS | Tanzu / TKG | kubectl / Nodes → Kubernetes API | Tanzu Kubernetes Grid (TKG) control plane API server access for cluster deployment and container management. |
| 22 | SSH | Core vSphere | Admin Workstation → ESXi / VCSA | Secure Shell (SSH) remote command-line administration, direct host troubleshooting, and support log collection. |
| 123 | UDP | All VMware | All Appliances → NTP Server | Network Time Protocol time synchronization (essential for Kerberos, SSL/TLS certificate validity, and HA clustering). |
| 53 | TCP / UDP | All VMware | All Appliances → DNS Server | Domain Name System forward and reverse name resolution across all vSphere management components and clusters. |
Detailed VMware Network & Firewall Architecture
1. VMware vSphere & vCenter Server Firewall Port Requirements
VMware vSphere 8 and 7 rely on a well-defined set of firewall rules to ensure high availability, administrative access, and inter-host communication:
- Port 443 (TCP - HTTPS): The primary entry point for the vSphere Client, VMware PowerCLI, REST APIs, and vSphere SDK. Internal microservices communicate with the VMware Identity Manager (vIDM) and Single Sign-On (SSO) over port 443.
- Port 902 (TCP/UDP - Hostd/Heartbeat): Bidirectional communication between vCenter Server and the ESXi hostd daemon. vCenter sends UDP heartbeats to ESXi hosts on port 902; if blocked for more than 60 seconds, hosts show as "Not Responding". It also carries Network File Copy (NFC) traffic for ISO transfers and OVF deployments.
- Port 5480 (TCP - VAMI): Dedicated port for the vCenter Server Appliance Management Interface (VAMI). Required for applying appliance patches, configuring network interfaces, monitoring CPU/RAM consumption, and executing file-based backups (FTP, FTPS, HTTP, HTTPS, SCP).
- Port 8000 (TCP - vMotion): Dedicated live migration stream. ESXi hosts initiate direct TCP connections on port 8000 over dedicated vMotion VMkernel ports with jumbo frames (MTU 9000).
2. VMware NSX Software-Defined Networking & Geneve Encapsulation
VMware NSX (formerly NSX-T) creates software-defined overlay networks using Tunnel Endpoints (TEPs):
- Port 6081 (UDP - Geneve): Geneve (Generic Network Virtualization Encapsulation) encapsulates layer-2 Ethernet frames into layer-3 UDP datagrams. Critical: Network underlay devices must allow UDP 6081 with a Minimum Transmission Unit (MTU) of at least 1600 bytes (1700 bytes strongly recommended) to avoid IP fragmentation.
- Port 1234 & 1235 (TCP - CCP): Central Control Plane (CCP) clustering and communication between NSX Manager nodes and transport node Local Control Plane (LCP) daemons.
- Port 179 (TCP - BGP): Border Gateway Protocol routing sessions between NSX Tier-0 Gateways and upstream physical Top-of-Rack (ToR) routers.
3. VMware vSAN & vSAN Express Storage Architecture (ESA)
VMware vSAN pools host NVMe/SSD storage into a resilient distributed object datastore:
- Port 12321 (TCP - CMDS): Cluster Monitoring, Directory, and Membership Services (CMDS) handles cluster state changes, disk grouping, and quorum configuration.
- Port 23451 (UDP - Gossip & Heartbeat): High-frequency cluster node heartbeats and health metrics gossip protocol.
- Port 2233 (TCP - RDT): Reliable Datagram Transport ensures high-throughput, low-latency object read/write operations and mirroring.
- Ports 2049 & 445 (TCP - File Services): Exposes vSAN Native File Services via NFS v3/v4.1 and SMB v2/v3 to enterprise file shares.
4. VMware Horizon & Unified Access Gateway (UAG) VDI Ports
Secure remote desktop and application access requires opening perimeter firewall ports to the Unified Access Gateway (UAG):
- Port 443 (TCP - HTTPS): Initial client authentication, XML broker negotiation, HTML5 web access, and tunneled protocol sessions.
- Port 8443 (TCP/UDP - Blast Extreme): High-performance Blast Extreme display protocol utilizing H.264/HEVC encoding and BEAT adaptive UDP transport for fluctuating bandwidth.
- Port 4172 (TCP/UDP - PCoIP): Teradici PCoIP display protocol stream for legacy clients and zero clients.
- Port 9427 & 32111 (TCP): Client Drive Redirection (CDR), Multimedia Redirection (MMR), and USB redirection when segregated from display protocols.
5. VMware HCX Cross-Cloud Migration & Hybrid Connectivity
VMware HCX abstracts on-premises and hyperscaler VMware Cloud (VMC on AWS, Azure VMware Solution, Google Cloud VMware Engine) resources:
- Port 4500 (UDP - IPsec WAN Interconnect): Encrypted WAN transport tunnel connecting source and target HCX Interconnect (IX) appliances across the public internet or private DirectConnect/ExpressRoute circuits.
- Port 9443 (TCP - HCX Manager): Web administration portal, fleet management, and site-pairing orchestration.
- Port 8123 (TCP - Bulk Migration): Manages replication-assisted vMotion and non-disruptive cold/bulk workload data transfers.
Discussion 0
Author Active`command`for inline code