Use the tables in this Appendix for guidance on firewall settings specific for the deployment of a VxRail cluster. Then use the links that are provided after the tables for firewall rules that are driven by product feature and use case.
The VxRail cluster needs to be able to connect to specific applications in your data center. DNS is required, and NTP is optional. Open the necessary ports to enable connectivity to the external syslog server, and for LDAP and SMTP.
Datacenter Application Access | ||||
Description | Source Devices | Destination Devices | Protocol | Ports |
DNS | VxRail Manager, Dell iDRAC | DNS Servers | UDP | 53 |
NTP Client | Host ESXi Management Interface, | NTP Servers | UDP | 123 |
SYSLOG | Host ESXi Management Interface, | Syslog Server | TCP | 514 |
LDAP | VMware vCenter Servers | LDAP Server | TCP | 389, 636 |
SMTP | Secure connect gateway VMs, vRealize Log Insight | SMTP Servers | TCP | 25 |
Open the necessary firewall ports to enable IT administrators to deploy the VxRail cluster.
Administration Access | ||||
Description | Source Devices | Destination Devices | Protocol | Ports |
ESXi Management | Administrators | Host ESXi Management Interface | TCP. UDP | 902 |
VxRail Management UI/Web Interfaces | Administrators | VMware vCenter Server, VxRail Manager, Host ESXi Management, | TCP | 80, 443 |
Dell server management | Administrators | Dell iDRAC | TCP | 623, 5900, 5901 |
SSH and SCP | Administrators | Host ESXi Management, | TCP | 22 |
If you plan to use a customer-managed vCenter server instead of deploying a vCenter server in the VxRail cluster, open the necessary ports so that the vCenter instance can connect to the ESXi hosts.
vCenter and vSphere | ||||
Description | Source Devices | Destination Devices | Protocol | Ports |
vSphere Clients to vCenter Server | vSphere Clients | vCenter Server | TCP | 5480, 8443, 9443, 10080, 10443 |
Managed Hosts to vCenter | Host ESXi Management | vCenter Server | TCP | 443, 902, 5988,5989, 6500, 8000, 8001 |
Managed Hosts to vCenter Heartbeat | Host ESXi Management | vCenter Server | UDP | 902 |
Other firewall port settings may be necessary depending on your data center environment. The list of documents in this table is provided for reference purposes.
Note: VxRail manages the VxRail Customer Firewall Rules interactive workbook. Access to the workbook requires Dell customer credentials. If you do not have Dell login credentials, contact your account team to download the tool for you.
Description | Reference |
VMware Ports and Protocols | |
Network port diagram for vSphere 6 | |
vSAN Ports Requirements | |
Dell iDRAC Port Requirements | |
Secure Connect Gateway Documentation | |
VMware vCenter Cloud Gateway Requirements |