Network port requirements for VMware NSX for vSphere 6.x
search cancel

Network port requirements for VMware NSX for vSphere 6.x

book

Article ID: 343367

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

This article provides information on the port requirements for the VMware NSX for vSphere.

For the most up-to-date information, see the Ports and Protocols Required by NSX section of the NSX Installation Guide.


Environment

VMware NSX for vSphere 6.1.x
VMware NSX for vSphere 6.3.x
VMware NSX for vSphere 6.0.x
VMware NSX for vSphere 6.4.x
VMware NSX for vSphere 6.2.x

Resolution

SourceTargetPortProtocolPurposeServices
ESXi HostsNSX Manager5671TCPRabbit MQ (messaging bus technology)Rabbit MQ
ESXi HostESXi Host6999UDPARP on VLAN LIFs 
ESXi HostNSX Controllers1234TCPCommunication between ESX Host and NSX Controller Clusters 
Client PCNSX Manager443TCPNSX Manager Admin InterfaceHTTPS
REST ClientNSX Manager443TCPNSX Manager REST APIHTTPS
Client PCNSX Manager80TCPNSX Manager VIB AccessHTTP
REST ClientNSX Controller443TCPNSX Controller REST APIHTTPS
NSX ControllerNSX Controller7777TCPInter-Controller RPC Port 
NSX ControllerNSX Controller30865TCPController Cluster - State Sync 
NSX ManagervCenter Server443,80TCPvSphere Web AccessHTTPS
NSX ManagervCenter Server902TCPvSphere Web AccessVMware Internal
NSX ManagerESXi Host443TCPManagement and provisioning connectionHTTPS
NSX ManagerESXi Host902TCPManagement and provisioning connectionVMware Internal
NSX ManagerDistributed Firewall443TCPManagement and provisioning connectionHTTPS
NSX ManagerDistributed Firewall902TCPManagement and provisioning connectionVMware Internal
VXLAN Termination End Point (VTEP)VXLAN Termination End Point (VTEP)8472UDPTransport Network encapsulation between VTEP end pointsVXLAN
NSX ManagerDNS Server53TCP/UDPDNS client connectionDNS
NSX ManagerNTP Time Server123TCP/UDPNTP client connectionNTP
NSX ManagerSyslog Server514TCP/UDPSyslog connectionSyslog
NSX ControllerNSX Controller2878, 2888, 3888TCPState Sync between controllersZookeeper
OVSDB ProtocolNSX Controller6640TCPOVSDB Protocol Integration 
Primary NSX ManagerSecondary NSX Manager443TCPCross-vCenter NSX Universal Sync Service 
Primary NSX ManagervCenter Server443TCPvSphere API 
Secondary NSX ManagervCenter Server443TCPvSphere API 
Primary NSX ManagerNSX Universal Controller Cluster443TCPNSX Controller REST API 
Secondary NSX ManagerNSX Universal Controller Cluster443TCPNSX Controller REST API 
ESXi HostNSX Universal Controller Cluster1234TCPNSX Control Plane Protocol 
ESXi HostPrimary NSX Manager5671TCPAMQP 
ESXi HostSecondary NSX Manager5671TCPAMQP 
ESXi HostvCenter Server443TCPVIB deployment/Host preparationEAM Service
vCenter ServerNSX Manager443TCPDownload Web Client plugin(vsmext.zip)Web Client
ESXi HostNSX Manager8301 and 8302UDPDVS Sync 
NSX ManagerESXi Host8301 and 8302UDPDVS Sync 
USVMNSX Manager5671TCPGuest Introspection


Additional Information

Starting with NSX 6.2.3, the default VXLAN port is 4789, the standard port assigned by IANA. Before NSX 6.2.3, the default VXLAN UDP port number was 8472.

VMware vSphere 6.0 supports VIB downloads over port 443 (instead of port 80). This port is opened and closed dynamically. The intermediate devices between the ESXi hosts and vCenter Server must allow traffic using this port.
 
VXLAN port 8472 is reserved or restricted for VMware use, any virtual machine cannot use this port for other purpose or for any other application.

For more information regarding port requirements with other VMware Products, see TCP and UDP Ports required to access VMware vCenter Server, VMware ESXi and ESX hosts, and other network components (1012382).

For more information on NSX ports, see the Ports Required for NSX Communication section in the NSX Installation and Upgrade Guide.