Applies to: VMware ESXi 9.x / 8.x / 7.x / 6.7 / 6.5 / 6.0 / 5.5 / 5.1 / 5.0
VMware introduced a built-in host firewall with ESXi 5.0. The same service-based firewall model continues in current ESXi releases: firewall rules are grouped into rulesets for services such as SSH, DNS, NTP, syslog, and management traffic.
The original version of this article focused on what was new in vSphere 5. This updated version keeps that history but focuses on how the ESXi firewall is managed today.
In This Article
- 1. How the ESXi Firewall Works
- 2. View Firewall Rules in the vSphere Client
- 3. View Firewall Rules with ESXCLI
- 4. Enable or Disable a Ruleset
- 5. Restrict a Ruleset by IP Address
- 6. System-Owned Rulesets
- 7. Key Takeaways
1. How the ESXi Firewall Works
The ESXi firewall is enabled by default and uses predefined rulesets that are associated with host services and features. Instead of opening arbitrary ports manually, you normally enable the ruleset for the service that needs network access.
A ruleset can also restrict access to specific IP addresses or subnets. This is useful for services such as SSH, where access should normally be limited to management networks rather than allowed from every source.
2. View Firewall Rules in the vSphere Client
On current vSphere versions, select the ESXi host and go to:
Configure > System > Firewall
The firewall view shows the available rulesets, whether they are enabled, and which IP addresses are allowed. An allowed-address value of All means the ruleset is not restricted to specific source IP addresses.
In the original vSphere 5 Client, the equivalent configuration was under Host > Configuration > Security Profile.
3. View Firewall Rules with ESXCLI
Check whether the ESXi firewall is enabled:
esxcli network firewall get
List the firewall rulesets:
esxcli network firewall ruleset list
List the allowed IP addresses for each ruleset:
esxcli network firewall ruleset allowedip list
4. Enable or Disable a Ruleset
For example, enable the SSH server ruleset:
esxcli network firewall ruleset set --ruleset-id=sshServer --enabled=true
Disable it again when it is no longer required:
esxcli network firewall ruleset set --ruleset-id=sshServer --enabled=false
Opening a firewall ruleset and starting the related service are separate operations. For example, enabling the SSH firewall ruleset does not by itself guarantee that the SSH service is running.
5. Restrict a Ruleset by IP Address
Where the ruleset supports manual IP restrictions, add the required management subnet first:
esxcli network firewall ruleset allowedip add --ruleset-id=sshServer --ip-address=192.0.2.0/24
Then disable unrestricted access for that ruleset:
esxcli network firewall ruleset set --ruleset-id=sshServer --allowed-all=false
Verify the result:
esxcli network firewall ruleset allowedip list --ruleset-id=sshServer
Be careful when restricting management-related rulesets remotely. Add the required management IP or subnet before removing the All setting so that you do not lock yourself out of the host.
6. System-Owned Rulesets
On current ESXi releases, some firewall rulesets are system-owned. These rules are controlled automatically by ESXi services and cannot be manually enabled, disabled, or have their allowed-IP list changed through the normal vSphere Client or ESXCLI commands.
Use the ruleset list to check whether a rule is user-configurable:
esxcli network firewall ruleset list
If Enable/Disable configurable or Allowed IP configurable is false, treat that ruleset as service-managed rather than forcing a manual change.
7. Key Takeaways
- The built-in ESXi firewall was introduced with ESXi 5.0 and remains part of current ESXi.
- Manage access through service-specific rulesets rather than arbitrary port changes.
- Use esxcli network firewall to inspect and manage rules from the command line.
- Restrict sensitive services such as SSH to known management networks where practical.
- Some modern ESXi rulesets are system-owned and should not be manually overridden.
References
- Broadcom – Managing ESXi Firewall Allowed IP Addresses
- Broadcom – System-Owned ESXi Firewall Rulesets

Cloud and infrastructure professional with nearly two decades of experience in enterprise IT environments, spanning public cloud, private cloud, and hybrid architectures.