Support > Knowledge Base
Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
Default Firewall Filter Does Not Allow for DNS Traffic Over TCP
Details
Consider the scenario where a license server for an ESX Server host might not be accessible because the reply to the DNS query does not fit into a single UDP packet. As a result, the DNS client on the ESX Server host attempts to resolve the license server hostname with a TCP DNS request. The default ESX Server firewall rule disallows such a request, and therefore, hostname is not resolved.
Solution
As a workaround, enable the ESX Server firewall to allow TCP DNS request. Log in to the service console and type the following command:
esxcfg-firewall -o 53,tcp,out,tcpdns
Feedback
Actions
- KB Article: 1000270
- Updated: Aug 14, 2009
- Products:
VMware ESX
VMware VirtualCenter - Product Versions:
VMware ESX 3.0.x
VMware VirtualCenter 2.0.x

