How to Configure the VMware ESXi Firewall

Applies to: VMware ESXi 9.x / 8.x / 7.x / 6.7 / 6.5 / 6.0 / 5.5 / 5.1 / 5.0

VMware introduced a built-in host firewall with ESXi 5.0. The same service-based firewall model continues in current ESXi releases: firewall rules are grouped into rulesets for services such as SSH, DNS, NTP, syslog, and management traffic.

The original version of this article focused on what was new in vSphere 5. This updated version keeps that history but focuses on how the ESXi firewall is managed today.

In This Article

1. How the ESXi Firewall Works

The ESXi firewall is enabled by default and uses predefined rulesets that are associated with host services and features. Instead of opening arbitrary ports manually, you normally enable the ruleset for the service that needs network access.

A ruleset can also restrict access to specific IP addresses or subnets. This is useful for services such as SSH, where access should normally be limited to management networks rather than allowed from every source.

2. View Firewall Rules in the vSphere Client

On current vSphere versions, select the ESXi host and go to:

Configure > System > Firewall

The firewall view shows the available rulesets, whether they are enabled, and which IP addresses are allowed. An allowed-address value of All means the ruleset is not restricted to specific source IP addresses.

In the original vSphere 5 Client, the equivalent configuration was under Host > Configuration > Security Profile.

3. View Firewall Rules with ESXCLI

Check whether the ESXi firewall is enabled:

esxcli network firewall get

List the firewall rulesets:

esxcli network firewall ruleset list

List the allowed IP addresses for each ruleset:

esxcli network firewall ruleset allowedip list

4. Enable or Disable a Ruleset

For example, enable the SSH server ruleset:

esxcli network firewall ruleset set --ruleset-id=sshServer --enabled=true

Disable it again when it is no longer required:

esxcli network firewall ruleset set --ruleset-id=sshServer --enabled=false

Opening a firewall ruleset and starting the related service are separate operations. For example, enabling the SSH firewall ruleset does not by itself guarantee that the SSH service is running.

5. Restrict a Ruleset by IP Address

Where the ruleset supports manual IP restrictions, add the required management subnet first:

esxcli network firewall ruleset allowedip add --ruleset-id=sshServer --ip-address=192.0.2.0/24

Then disable unrestricted access for that ruleset:

esxcli network firewall ruleset set --ruleset-id=sshServer --allowed-all=false

Verify the result:

esxcli network firewall ruleset allowedip list --ruleset-id=sshServer

Be careful when restricting management-related rulesets remotely. Add the required management IP or subnet before removing the All setting so that you do not lock yourself out of the host.

6. System-Owned Rulesets

On current ESXi releases, some firewall rulesets are system-owned. These rules are controlled automatically by ESXi services and cannot be manually enabled, disabled, or have their allowed-IP list changed through the normal vSphere Client or ESXCLI commands.

Use the ruleset list to check whether a rule is user-configurable:

esxcli network firewall ruleset list

If Enable/Disable configurable or Allowed IP configurable is false, treat that ruleset as service-managed rather than forcing a manual change.

7. Key Takeaways

  • The built-in ESXi firewall was introduced with ESXi 5.0 and remains part of current ESXi.
  • Manage access through service-specific rulesets rather than arbitrary port changes.
  • Use esxcli network firewall to inspect and manage rules from the command line.
  • Restrict sensitive services such as SSH to known management networks where practical.
  • Some modern ESXi rulesets are system-owned and should not be manually overridden.

References

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.