A SERVICE OF

logo

VMware, Inc. 77
Chapter 6 Installing VMware Infrastructure Management
Duringnormaloperations,VirtualCenterislisteningfordatafromitsmanagedhosts
andclientsondesignatedports.Additionally,themanagedhostsarelisteningfordata
fromVirtualCenterondesignatedports.Ifafirewallexistsbetweenanyofthese
elements,aholemustbecreatedtoallowdatatransfertothesedesignated
ports.
Thefollowingsectionsdescribehowtofacilitatethiscommunication.Forinformation
onSDKcommunications,seetheVMwareSDKdocumentation.Foramorethorough
discussionoffirewallconfiguration,seetheServerConfigurationGuide.
Connecting to Your VirtualCenter Server Through a Firewall
ThedefaultportsthattheVirtualCenter Serverusestolistenforconnectionsfromthe
VI Clientareports80,443,and902.TheVirtualCenter Serveralsousesport443tolisten
fordatatransferfromtheVIWebAccessClientandotherSDKclients.
IfyouhaveafirewallbetweenyourVirtualCenter Serverandits
clients,youmust
configureameansfortheVirtualCenter Servertoreceivedatafromthem.
ToenabletheVirtualCenter ServertoreceivedatafromtheVI Client,openports80,
443,and902inthefirewalltoallowdatatransferfromtheVI Clienttothe
VirtualCenter Server.ToenabletheVirtualCenter Servertoreceivedatafrom
theVI
WebAccessClient,openport443inthefirewall.Consultyourfirewallsystem
administratorforadditionalinformationonconfiguringportsinafirewall.
IfyouwanttheVirtualCenter ServertouseadifferentporttoreceiveVI Clientdata,see
BasicSystemAdministration.
TotunneltheVI Clientdatathroughthefirewall
tothereceivingportonthe
VirtualCenter Server,seeBasicSystemAdministration.VMwaredoesnotrecommended
thismethodbecauseitdisablestheVirtualCenterconsolefunction.
Connecting to Your Managed Hosts Through a Firewall
Port902isthedefaultportthatVirtualCenterusestosenddatatothemanagedhosts.
IfyouhaveafirewallbetweenyourVirtualCenter ServerandVirtualCentermanaged
host,youmustconfigureameansfortheVirtualCenter Servertosenddatatothe
VirtualCentermanagedhost.
Ifyouhaveafirewallbetweentwo
VirtualCentermanagedhostsandyouwantto
performanysourceortargetactivities,suchasmigrationorcloning,youmust
configureameansforthemanagedhoststoreceivedata.
ManagedhostsalsosendaregularheartbeatoverUDPport902tothe
VirtualCenter Server.Thisportmustnotbeblocked
byfirewalls.