---
name: vmwaresolutions-vmwaresol_ports-deploy-day2ops
title: Ports that are used for deployment and Day 2 operations
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2025-10-24
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Ports that are used for deployment and Day 2 operations
{: #vmwaresol_ports-deploy-day2ops}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

The following table provides information about the ports for deployment and Day 2 operations. For more information about the ports that are used by the add-on services, see [Ports for services](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vmwaresol_ports-services&format=markdown).

Review the following information about the ports described in the [table](#vmwaresol_ports-deploy-day2ops-table):

* Windows® Active Directory™ has two options: single Windows Virtual Service Instance (VSI) and two HA-dedicated Windows Server virtual machines (VMs). For single Windows VSI, the VSI is in the primary subnet. For Windows Server VMs, the VMs are in the [infrastructure VMs](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vmwaresol_ports-vlans-subnets&format=markdown) subnet.
* IBM Cloud&reg; infrastructure services network subnets vary from data center to data center. For more information, see [IBM Cloud IP ranges](https://cloud.ibm.com/docs/infrastructure-hub?topic=infrastructure-hub-ibm-cloud-ip-ranges&format=markdown).
* Some Windows resources in your environment might use classic infrastructure services in Dallas.
* IBM Cloud endpoint service network includes `166.8.0.0/14`.
* IBM CloudDriver is an ephemeral VSI that is deployed by the IBM Cloud automation to configure your instance. While IBM CloudDriver is being bootstrapped, it uses an ephemeral primary IP address. However, after bootstrapping, it uses a predictable portable IP address that you can find on your instance details page. For more information, see [IBM CloudDriver](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-design_infrastructuremgmt&format=markdown#design_infrastructuremgmt-cloud-driver).
* Infrastructure VMs refer to the private portable subnet allocated for use by vCenter, NSX manager, the cloud driver
* Depending on your mode of deployment, your Windows Active Directory domain controllers can be VSIs on a primary subnet, or VMs on a portable subnet.

| Source | Subnet, IP range | Target | Subnet, IP range | Port | Protocol | Purpose | Service |
|:------ |:---------------- |:------ |:---------------- |:---- |:-------- |:------- |:------- |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | IBM Cloud Service - Cloud Object Storage \n `10.1.129.0/24`[^vssreqa] | IBM Cloud infrastructure services network | 443 | TCP | Use IBM Cloud Object Storage service | HTTPS |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | IBM Cloud Service - RabbitMQ `166.9.12.55` \n `166.9.14.30` \n `166.9.16.36` \n IBM Cloud Service - IBM Cloud Logs[^vssreqb] | IBM Cloud endpoint service network | 31795 | TCP | Use IBM Cloud RabbitMQ and IBM Cloud Logs services | |
| IBM CloudDriver | Private primary subnet | vCenter Server | Infrastructure VMs | | ICMP | Install and configure vCenter Server | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | vCenter Server | Infrastructure VMs | 22 | TCP | Set up and configure vCenter Server | SSH |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | vCenter Server | Infrastructure VMs | 443 | TCP | Install and configure vCenter Server and cluster | SSH |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | vCenter Server | Infrastructure VMs | 9443 | TCP | Install and configure vCenter Server and cluster | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | vCenter Server | Infrastructure VMs | 5489 | TCP | Install and configure vCenter Server and cluster | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | ESXi™ host | Private primary subnet | 22 | TCP | Set up, configure, and apply patches to ESXi host | SSH |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | ESXi vMotion | vMotion traffic | | ICMP | Set up ESXi network | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | ESXi vSAN™ | vSAN traffic | | ICMP | Set up ESXi network | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | ESXi shared storage | Shared storage traffic | | ICMP | Set up ESXi network | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | Customer edge private | Customer edge gateway private | | ICMP | Set up NSX edge network | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | Windows Active Directory | Private primary subnet (for Windows VSI)/ \n Infrastructure VMs (for Windows VMs) | 5986 | TCP | Set up and configure Windows Active Directory and DNS | |
| IBM CloudDriver | Private primary subnet | NSX Manager | Infrastructure VMs | | ICMP | Install and set up NSX Manager | |
| IBM CloudDriver | Private primary subnet | NSX Manager | Infrastructure VMs | 443 | TCP | Set up and configure NSX Manager | HTTPS |
| IBM CloudDriver | Private primary subnet | NSX Manager | Infrastructure VMs | 80 | TCP | Set up and configure NSX Manager | HTTP |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure provisioning API \n `10.0.80.0/25` | IBM Cloud infrastructure services network | 443 | TCP | Order and provision IBM Cloud infrastructure resources | HTTPS |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure DNS service \n `10.0.80.11` \n `10.0.80.12` | IBM Cloud infrastructure services network | 53 | UDP | Use IBM Cloud infrastructure DNS service | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure NTP service. | IBM Cloud infrastructure services network. For more information, see [Synchronizing app time to the IBM Cloud NTP service](https://cloud.ibm.com/docs/infrastructure-hub?topic=infrastructure-hub-ntp-service-overview&format=markdown). | 123 | UDP | Use IBM Cloud infrastructure NTP service | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure endurance storage | IBM Cloud infrastructure services network | Any | ICMP and TCP | Set up endurance storage for ESXi host | |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | Usage Meter Appliance | Infrastructure VMs | 443 | TCP | Set and configure Usage Meter and add metered products | HTTPS |
| IBM CloudDriver | Private primary subnet \n Infrastructure VMs | Usage Meter Appliance | Infrastructure VMs | 22 | TCP | Install and configure Usage Meter | SSH |
| IBM CloudDriver |   | IBM Cloud Service \n `10.221.68.39` |   | 514 | TCP |   |   |
| IBM CloudDriver |   | Internet |   |   |   |   | HTTPS |
| IBM CloudDriver \n Windows Active Directory (VSI) | Private primary subnet | IBM Cloud infrastructure engine | IBM Cloud infrastructure services network | 80 | TCP | Provision IBM CloudDriver and Windows Active Directory (VSI) | |
| Windows Active Directory | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure DNS service \n `10.0.80.11` \n `10.0.80.12` | IBM Cloud infrastructure services network | 53 | UDP | Use IBM Cloud infrastructure DNS service | |
| Windows Active Directory | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure NTP service | IBM Cloud infrastructure services network | 123 | UDP | Use IBM Cloud infrastructure NTP service | |
| Windows Active Directory | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure WSUS service | IBM Cloud infrastructure services network | 80 | TCP | Use IBM Cloud infrastructure WSUS service | HTTP |
| Windows Active Directory | Private primary subnet \n Infrastructure VMs | IBM Cloud infrastructure Windows KMS service | IBM Cloud infrastructure services network | 1688 | TCP | Use IBM Cloud infrastructure Windows KMS service | |
| ESXi host | Private primary subnet | IBM Cloud infrastructure NTP service | IBM Cloud infrastructure services network | 123 | UDP | Use IBM Cloud infrastructure NTP service | |
| ESXi host shared storage | ESXi shared storage | IBM Cloud infrastructure endurance storage | IBM Cloud infrastructure services network | 111, 635, and 2049 | TCP and UDP | Use IBM Cloud infrastructure endurance storage | |
| vCenter Server | Infrastructure VMs | IBM Cloud infrastructure NTP service | IBM Cloud infrastructure services network | 123 | UDP | Use IBM Cloud infrastructure NTP service | |
| NSX Manager | Infrastructure VMs | IBM Cloud infrastructure NTP service | IBM Cloud infrastructure services network | 123 | UDP | Use IBM Cloud infrastructure NTP service | |
| NSX Manager | Infrastructure VMs | TEP subnet | TEP traffic | 443 |  |  |  |
| NSX Manager | Infrastructure VMs | Customer edge subnet | Customer edge private traffic | 443 |  |  |  |
| IBM Cloud infrastructure engine | IBM Cloud infrastructure services network | IBM CloudDriver \n Windows Active Directory (VSI) | Private primary subnet | Any | TCP and UDP | Provision IBM CloudDriver and Windows Active Directory (VSI) |
| IBM Cloud infrastructure engine | IBM Cloud infrastructure services network | ESXi host management0 | Private primary subnet | 623 | TCP and UDP | IBM Cloud infrastructure IPMI |   |
{: caption="Ports for deployment and Day 2 operations" caption-side="bottom"}
{: #vmwaresol_ports-deploy-day2ops-table}

[^vssreqa]: Flexible instances require access to Cloud Object Storage, RabbitMQ, and IBM Cloud Logs.
[^vssreqb]: Flexible instances require access to Cloud Object Storage, RabbitMQ, and IBM Cloud Logs.

## Related links
{: #vmwaresol_ports-deploy-day2ops-related}

* [Ports used by VMware components](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vmwaresol_ports-vmwareuses&format=markdown)