<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can not disable vsanvp firewall rule... in ESXi Discussions</title>
    <link>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799174#M175413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to tighten a little bit security of my solo ESXi 6.0 server by disabling unnecessary services/rules, so I want to disable firewall rule for vsanvp. But when I try it (using native client), all I get is the message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Call "HostFirewallSystem.DisableRuleset" for object "firewallSystem" on ESXi "&amp;lt;my_esxi_IP&amp;gt;" failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Security Profile still shows I have allowed incomming/outgoing connections for vsanvp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vSphere 6.0 docu says:&lt;/P&gt;&lt;P&gt;VSAN VASA Vendor Provider. Used by the Storage Management Service (SMS) that is part of vCenter to access information about Virtual SAN storage profiles, capabilities, and compliance. If disabled, Virtual SAN Storage Profile Based Management (SPBM) does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I'm using neither vCenter nor virtual san-storage. So why I still can not disable firewall rule for vsanvp?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Sep 2015 18:32:09 GMT</pubDate>
    <dc:creator>JarryG</dc:creator>
    <dc:date>2015-09-24T18:32:09Z</dc:date>
    <item>
      <title>Can not disable vsanvp firewall rule...</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799174#M175413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to tighten a little bit security of my solo ESXi 6.0 server by disabling unnecessary services/rules, so I want to disable firewall rule for vsanvp. But when I try it (using native client), all I get is the message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Call "HostFirewallSystem.DisableRuleset" for object "firewallSystem" on ESXi "&amp;lt;my_esxi_IP&amp;gt;" failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Security Profile still shows I have allowed incomming/outgoing connections for vsanvp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vSphere 6.0 docu says:&lt;/P&gt;&lt;P&gt;VSAN VASA Vendor Provider. Used by the Storage Management Service (SMS) that is part of vCenter to access information about Virtual SAN storage profiles, capabilities, and compliance. If disabled, Virtual SAN Storage Profile Based Management (SPBM) does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I'm using neither vCenter nor virtual san-storage. So why I still can not disable firewall rule for vsanvp?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Sep 2015 18:32:09 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799174#M175413</guid>
      <dc:creator>JarryG</dc:creator>
      <dc:date>2015-09-24T18:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can not disable vsanvp firewall rule...</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799175#M175414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having the same problem.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In lieu of disabling it entirely, I restricted it to an unused IP range.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'andale mono', times;"&gt;esxcli network firewall ruleset allowedip add -i 10.x.y.z/31 -r vsanvp&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Nov 2015 04:17:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799175#M175414</guid>
      <dc:creator>danpritts3</dc:creator>
      <dc:date>2015-11-19T04:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can not disable vsanvp firewall rule...</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799176#M175415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interested to know if either of you had an update on a fix other than removing IP range?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2016 22:01:36 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799176#M175415</guid>
      <dc:creator>AndyDodsworth</dc:creator>
      <dc:date>2016-06-16T22:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can not disable vsanvp firewall rule...</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799177#M175416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't it is recommended to disable "vsanvp" firewall rule. This is a required parameter on a ESXi host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Vmware KB for reference : &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://kb.vmware.com/kb/2092598" rel="nofollow"&gt;http://kb.vmware.com/kb/2092598&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this answers your query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jagadish M S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jun 2016 04:58:41 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/Can-not-disable-vsanvp-firewall-rule/m-p/1799177#M175416</guid>
      <dc:creator>msjagadish</dc:creator>
      <dc:date>2016-06-24T04:58:41Z</dc:date>
    </item>
  </channel>
</rss>

