Host Profiles do not save firewall rulesets for non-default firewall rules
search cancel

Host Profiles do not save firewall rulesets for non-default firewall rules

book

Article ID: 342622

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESXi

Issue/Introduction

Symptoms:
  • Firewall rulesets for non-default firewall rules are not saved in a host profile.
  • Unable to extract custom firewall rules when a host profile is created from a host.
  • If the host profile is edited to add a custom firewall rule, this rule is not applied to the host when the host profile is applied.
  • Allowed IP address ranges are not set and show all IP addresses are allowed after applying compliance.


Environment

VMware vSphere ESXi 6.0
VMware vCenter Server 6.0.x
VMware vSphere ESXi 5.5
VMware vSphere ESXi 5.1

Resolution

This behavior is by design. In the host profile firewall profile implementation, these firewall rulesets are ignored by the host profile compliance check:
  • iSCSI
  • nfsClient
  • fdm
  • faultTolerance
  • vpxHeartbeats
  • netDump
  • autodeploy

These rulesets are controlled by their corresponding services, so any custom setting for these rulesets is ignored by the host profile engine.
All other firewall rules can be configured through the firewall profile.

Additional Information

For more information about using Host Profiles, see the Using Host Profiles section in the vSphere Host Profiles guide.
ホスト プロファイルにデフォルト以外のファイアウォール ルールのファイアウォール ルールセットが保存されない