vCenter : block-unused-ports

Information

Blocking unneeded ports can militate against general attacks on the Windows system. A local firewall on the Windows system of vCenter, or a network firewall, can be used to block access to ports not specifically being used by vCenter. Here is a partial list of examples of where ports might be blocked: (636/TCP) If the vCenter will not be part of a linked-mode vCenter group; (1521/TCP) If the vCenter DB is not Oracle.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx