Port numbers that must be open for vSphere Replication 8.x
search cancel

Port numbers that must be open for vSphere Replication 8.x

book

Article ID: 312798

calendar_today

Updated On:

Products

VMware Live Recovery VMware vSphere ESXi

Issue/Introduction


This article provides information about port numbers that must be open for vSphere Replication 8.x.

Environment

VMware vSphere Replication 6.1.x
VMware vSphere Replication 6.5.x
VMware vSphere Replication 8.x
VMware vSphere Replication 6.0.x
VMware vSphere Replication 5.8.x

Resolution


vSphere Replication appliance network ports

The vSphere Replication appliance requires certain ports to be open.

NOTE: vSphere Replication Management servers must have NFC traffic access to target ESXi hosts. VR 8.8 no longer uses port # 80 for communication. The below ports are a requirement of 8.7 and below versions. For 8.8 and above, please check - Services, Ports, and External Interfaces That the vSphere Replication Virtual Appliance Uses

Use netcat command when testing from ESXi to appliances (vCenter/SRM/VR)
Use curl command when testing between appliances (vCenter/SRM/VR)

curl -v telnet://Target IP address:31031 (desired port #)
nc –zv xxx.xxx.xx.xxx 31031 (desired port #)

Default PortProtocol or DescriptionSourceTargetEndpoints or Consumers
80TCPvSphere Replication applianceAll local and remote PSCs in same SSO domain (only if external PSC is used)All management traffic to the vSphere Replication appliance goes to port 80 on the vCenter Server proxy system.
80TCPvSphere Replication applianceRemote vCenter Server and local vCenter ServerAll management traffic to the vSphere Replication appliance goes to port 80 on the vCenter Server proxy system.
80HTTPvSphere Replication server in the vSphere Replication applianceESXi host (intra-site)Used to establish the connection before initial replication starts
443TCPvSphere Replication applianceAll local and remote PSCs in same SSO domain (only if external PSC is used)All management traffic to the vSphere Replication appliance
443TCPvSphere Replication appliance

Local and remote vCenter Server

All management traffic to the vSphere Replication appliance
443TCPNew applianceESXi that hosts the old applianceApplicable only for VR 8.x migration upgrade
902TCP and UDPvSphere Replication server in the vSphere Replication appliance on secondary siteESXi host (intra-site only) on secondary siteUsed by vSphere Replication servers to send replication traffic to the destination ESXi hosts.
5480vSphere Replication appliance virtual appliance management interface (VAMI) Web UIBrowservSphere Replication 8.x appliance and laterAdministrator's Web browser.
7444TCPvSphere Replication appliancevCenter Server (intra-site) 
7444TCPvCenter ServerAll local and remote PSCs 
8043SOAPvCenter ServervSphere Replication applianceFrom the vCenter Server to the vSphere Replication appliance (intra-site only).
8123SOAPvSphere Replication appliancevSphere Replication serverManagement traffic from the vSphere Replication appliance to additional vSphere Replication servers (intra-site only).
10443HTTPSvSphere Web Client on the primary sitevCenter Server / Inventory Service on the secondary siteThe vSphere Replication UI uses the Inventory Service of the remote vCenter Server to list target datastores.
31031
  • Initial replication traffic in vSphere Replication.
  • Initial and ongoing replication traffic in vSphere Replication
ESXi host on primary sitevSphere Replication server in the vSphere Replication appliance on the secondary site or an external VRS on secondary site.From the ESXi host at the protected site to the vSphere Replication appliance or vSphere Replication server at the recovery site.
     
8043SOAPvSphere Replication Management Server -VRMS vSphere Replication Management Server -VRMS From the VRMS of the Primary Site to the VRMS on the DR site - Port should be open Across Sites 
 

vSphere Replication server network ports

If you deploy additional vSphere Replication servers, ensure that the subset of the ports that vSphere Replication servers require are open on those servers.
 
Default PortProtocol or DescriptionSourceTargetEndpoints or Consumers
902TCP and UDPvSphere Replication server in the vSphere Replication appliance on secondary siteESXi host (intra-site only) on secondary siteTraffic (specifically the NFC service to the destination ESXi servers) between the vSphere Replication server and the ESXi hosts on the same site.
5480VAMI Web UI for any additional vSphere Replication serversBrowservSphere Replication serverAdministrator's Web browser.
8123SOAPvSphere Replication management servervSphere Replication serverManagement traffic from the vSphere Replication appliance or VRMS to the vSphere Replication servers (intra-site only).
31031
  • Initial replication traffic in vSphere Replication
  • Initial and ongoing replication traffic in vSphere Replication
ESXi host on primary sitevSphere Replication serverFrom the ESXi host at the protected site to the vSphere Replication appliance or vSphere Replication server at the recovery site.
32032
  • Initial and forward replication traffic with network encryption from the ESXi host at the source site to the vSphere Replication appliance or vSphere Replication server at the target site.
ESXi host on the source sitevSphere Replication server at the target siteEncrypted traffic. If you configure a replication of an encrypted VM, the network encryption is automatically turned on and cannot be disabled
     


Network ports required for replications to Cloud

When you create a connection to the cloud, the vCloud Tunneling Agent in the vSphere Replication appliance creates a tunnel to secure the transfer of replication data to your cloud Organization.

Default PortProtocol or DescriptionSourceTargetEndpoints or Consumers
80TCPThe ESXi host at the protected site.The vCenter Server at the protected site.The vCenter Server reverse proxy forwards VIB (vCloud Air DRaaS firewall rules) download request to vSphere Replication appliance.
443TCPvSphere Replication appliance at the protected site.vCloud APIvSphere Replication appliance connects to this port to send replication data to a cloud organization.
10000-10010TCPThe ESXi host at the protected site.The vSphere Replication appliance at the protected site.The vCloud Tunneling Agent opens one of these ports on the vSphere Replication appliance. ESXi hosts connect to that port to send replication data to a cloud organization.
 
 

Additional Information

For more detailed port number information, please refer to this link -  Network Ports for VMware Site Recovery 

For translated versions of this article, see: