Aller au contenu principal

06 — Ports Réseau à Ouvrir — VCF Automation 9.1

Référence officielle : ports.broadcom.com/home/VMware-Cloud-Foundation
Network Diagrams VCF


1. Conventions

SymboleSignification
Flux initié par la source vers la destination
TCPProtocole TCP
UDPProtocole UDP
BidirectionnelFlux dans les deux sens

2. Flux VCF Automation → Infrastructure

2.1 VCF Automation ↔ vCenter

SourceDestinationPortProtoUsage
VCF Automation NodesvCenter Server443TCPAPI vSphere / provisioning VMs
VCF Automation NodesvCenter Server9087TCPUpload OVF/ISO via Content Library
VCF Automation NodesESXi Hosts443TCPAccès direct ESXi (clonage disque)
VCF Automation NodesESXi Hosts902TCPvSphere Agent (NFC - transfert données)
VCF Automation NodesvCenter Server5480TCPvCenter Appliance Management (VAMI)

2.2 VCF Automation ↔ NSX

SourceDestinationPortProtoUsage
VCF Automation NodesNSX Manager443TCPAPI NSX — provisioning réseaux/segments
VCF Automation NodesNSX Manager8444TCPNSX Manager API (interne)
NSX ManagerVCF Automation Nodes443TCPCallbacks NSX vers VCF Automation

2.3 VCF Automation → Stockage (vSAN / NFS / iSCSI)

SourceDestinationPortProtoUsage
VCF Automation NodesHôtes ESXi2049TCP/UDPNFS (si NFS datastore)
VCF Automation NodesiSCSI targets3260TCPiSCSI (si applicable)

3. Flux VCF Automation ↔ Fleet Lifecycle / VCF Operations

SourceDestinationPortProtoUsage
Fleet LCVCF Automation Nodes443TCPLCM — Installation, upgrade, Day-N actions
Fleet LCVCF Automation Nodes30000TCPVMSP internal API (bootstrap)
Fleet LCVCF Automation Nodes30005TCPVMSP webhooks (disk mount, SFTP config...)
VCF Automation NodesFleet LC (VCF Operations)443TCPRegistration, service registry
VCF Automation NodesVCF Operations443TCPMonitoring, métriques, intégration
VCF OperationsVCF Automation Nodes443TCPCollecte métriques, alertes
VCF Operations Cloud ProxyVCF Automation Nodes443TCPCollecte données via cloud proxy

4. Flux VCF Automation ↔ Identity Broker / Authentification

SourceDestinationPortProtoUsage
Navigateurs utilisateursVCF Automation443TCPAccès UI
VCF Automationidbroker443TCPAuthentification SSO
idbrokerActive Directory / LDAP389TCPLDAP sans TLS
idbrokerActive Directory / LDAPS636TCPLDAP avec TLS
idbrokerActive Directory3268TCPGlobal Catalog LDAP
idbrokerActive Directory3269TCPGlobal Catalog LDAPS
VCF AutomationDNS53TCP/UDPRésolution DNS
VCF AutomationNTP123UDPSynchronisation NTP

5. Flux VCF Automation ↔ Clouds Publics (Hybrid)

SourceDestinationPortProtoUsage
VCF AutomationAWS API Endpoints443TCPAWS Cloud Account
VCF AutomationAzure API Endpoints443TCPAzure Cloud Account
VCF AutomationGCP API Endpoints443TCPGCP Cloud Account
VCF AutomationVMC on AWS443TCPVMware Cloud on AWS

6. Flux VCF Automation — Backup SFTP

SourceDestinationPortProtoUsage
VCF Automation NodesServeur SFTP22TCPBackup full (24h) + incrémental (15 min)

7. Flux VCF Automation — Kubernetes interne

Ces ports sont nécessaires entre les nœuds du cluster VCF Automation et entre les nœuds K8s du VCF Services Runtime.

SourceDestinationPortProtoUsage
Node → NodeNode → Node6443TCPKubernetes API Server
Node → NodeNode → Node2379-2380TCPetcd (KV store cluster state)
Node → NodeNode → Node10250TCPKubelet API
Node → NodeNode → Node10255TCPKubelet read-only
Node → NodeNode → Node8472UDPFlannel/VXLAN overlay réseau K8s
Node → NodeNode → Node179TCPBGP (si Calico CNI)

8. Flux Load Balancer ↔ VCF Automation (Cluster uniquement)

SourceDestinationPortProtoUsage
Load BalancerVCF Automation Node 1-3443TCPHTTPS traffic (principal)
Load BalancerVCF Automation Node 1-38443TCPAPI interne
Health Check LBVCF Automation Node 1-3443TCPHealth check HTTPS /health
Clients/UtilisateursLoad Balancer VIP443TCPAccès UI et API VCF Automation

9. Flux VCF Automation → Dépôt logiciel (Software Depot)

SourceDestinationPortProtoUsage
Fleet LifecycleBroadcom Depot (Online)443TCPTéléchargement binaires upgrade/patch
Fleet LifecycleSoftware Depot (Offline)443TCPDépôt local VCF
VCF AutomationSoftware Depot443TCPBinaires applicatifs

10. Flux Gestion / Administration

SourceDestinationPortProtoUsage
Admin / JumpboxVCF Automation Nodes22TCPSSH (admin d'urgence, vmware-system-user)
Admin / JumpboxVCF Automation443TCPAccès UI administration
SDDC ManagerVCF Automation Nodes22TCPSSH pour opérations LCM
SDDC ManagerVCF Automation Nodes443TCPAPI calls LCM

11. Tableau récapitulatif — Firewall Rules

Pour faciliter la configuration du firewall, voici la synthèse des règles à créer :

Règle 1 : Accès utilisateurs → VCF Automation

Source : Réseaux utilisateurs (VLAN Corporate, VPN...)
Destination : VCF Automation VIP (ou IP nœud si simple)
Ports : TCP 443
Action : ALLOW

Règle 2 : VCF Automation → Infrastructure vSphere

Source : Réseau VCF Automation (Cluster CIDR + Node IPs)
Destination : vCenter(s), ESXi hosts
Ports : TCP 443, 902, 9087, 5480
Action : ALLOW

Règle 3 : VCF Automation → NSX

Source : Réseau VCF Automation
Destination : NSX Manager(s)
Ports : TCP 443, 8444
Action : ALLOW

Règle 4 : Fleet Lifecycle → VCF Automation (LCM)

Source : VCF Services Runtime CIDR
Destination : VCF Automation Node IPs
Ports : TCP 443, 30000, 30005
Action : ALLOW

Règle 5 : VCF Automation → SFTP Backup

Source : VCF Automation Node IPs
Destination : Serveur SFTP
Ports : TCP 22
Action : ALLOW

Règle 6 : VCF Automation → Identity Broker → AD

Source : VCF Automation
Destination : VCF Identity Broker
Ports : TCP 443
Action : ALLOW

Source : VCF Identity Broker
Destination : Active Directory
Ports : TCP 389, 636, 3268, 3269
Action : ALLOW

Règle 7 : Inter-nœuds cluster K8s

Source : VCF Automation Node IPs
Destination : VCF Automation Node IPs
Ports : TCP 6443, 2379-2380, 10250, 10255, 179 / UDP 8472
Action : ALLOW (bidirectionnel)

Règle 8 : VCF Automation → DNS/NTP

Source : VCF Automation Node IPs + Cluster CIDR
Destination : Serveurs DNS + NTP
Ports : TCP/UDP 53, UDP 123
Action : ALLOW

Règle 9 : Admin SSH (accès limité)

Source : Réseau Admin / Jumpbox
Destination : VCF Automation Node IPs
Ports : TCP 22
Action : ALLOW (limité aux IPs d'administration)

Règle 10 : VCF Automation → Clouds Publics (optionnel)

Source : VCF Automation Node IPs
Destination : Internet (AWS/Azure/GCP endpoints)
Ports : TCP 443
Action : ALLOW (via proxy si applicable)

12. Configuration Proxy HTTP (optionnel)

Si votre environnement utilise un proxy HTTP/HTTPS pour l'accès Internet :

ParamètreDescription
Proxy URLhttp://proxy.domain.local:3128
Proxy HTTPShttps://proxy.domain.local:3128
No Proxylocalhost,127.0.0.1,*.domain.local,vCenter-IP,NSX-IP,...
Auth proxyBasic Auth ou NTLM si requis

⚠️ Le proxy doit permettre l'accès à depot.broadcom.com pour les mises à jour.


📖 Termes spécifiques VCF 9 : GLOSSARY.md

Précédent → 05_sizing_ha_multisite.md
Suivant → 07_client_workbook.md