Port | Description |
221 | During Virtual Replication Appliance (VRA) installation on ESXi 4.x and 5.x hosts for communication between the ZVM and the ESXi hosts IPs and for ongoing communication between the ZVM in the cloud site – but not the customer site – and a Zerto Cloud Connector. |
443 | During VRA installation on ESX/ESXi hosts for communication between the ZVM and the ESX/ESXi hosts IPs and for ongoing communication between the ZVM and vCenter Server and vCloud Director. |
4005 | Log collection between the ZVM and VRAs on the same site. |
4006 | TCP communication between the ZVM and VRAs and the VBA on the same site. |
4007 | TCP control communication between protecting and recovering VRAs and between a Zerto Cloud Connector and VRAs. |
4008 | TCP communication between VRAs to pass data from protected virtual machines to a VRA on a recovery site and between a Zerto Cloud Connector and VRAs. |
4009 | TCP communication between the ZVM and site VRAs to handle checkpoints. |
5672 | TCP communication between the ZVM and vCloud Director for access to AMQP messaging. |
9080 | HTTP communication between the ZVM and Zerto internal APIs, a Zerto Cloud Manager (ZCM), cmdlets, and a VSS Agent. |
90812 | TCP communication between paired ZVMs3 and between a ZVM and a Zerto Cloud Connector. |
9082 and up | When a cloud service provider supplies DRaaS – Two TCP ports for each VRA (one for port 4007 and one for port 4008) accessed via the Zerto Cloud Connector installed by the cloud service provider. There is directionality to these ports. Zerto recommends using a port range starting with port 9082. For example, Customer A network has 3 VRAs and customer B network has 2 VRAs and the cloud service provider network has 4 VRAs, then the following ports must be open in the firewall for each cloud: The cloud service provider’s VRAs need to use 6 ports to reach customer A’s VRAs, while customer A’s VRAs need 8 ports to reach the cloud’s VRAs. The cloud service provider’s VRAs need to use 4 ports to reach customer B’s VRAs, while customer B’s VRAs need 8 ports to reach the cloud’s VRAs. |
9180 | Communication between the VBA and VRA. |
9669 | HTTPS communication between the machine running the Zerto User Interface and a ZVM, and for invoking Zerto RESTful APIs. |
9779 | HTTPS communication between the Zerto Self-Service Portal for in-cloud (ICDR) customers and a ZVM. |
9989 | HTTPS communication between a browser and the Zerto Cloud Manager. |
Category | Privilege | Notes |
Alarms | Create alarm | Only during install and uninstall |
Remove alarm | ||
Authorization | Modify permission | Only during install and uninstall |
Modify role | ||
Reassign role permissions | ||
Datastore | Allocate space | For source/target replication of datastores |
Browse datastore | ||
Low level file operations | ||
Move datastore | ||
Remove file | ||
Update virtual machine files | ||
Datastore cluster | Configure a datastore cluster | For installation of VRAs |
Extension | Register extension | Only during install and uninstall |
Unregister extension | ||
Update extension | ||
Folder | Create folder | |
Delete folder | ||
Move folder | ||
Global | Cancel task | |
Diagnostics | ||
Disable methods | ||
Enable methods | ||
Global tag | ||
Log event | ||
Manage custom attributes | ||
Script action | ||
Set custom attribute | ||
Host > Configuration | Advanced settings | |
Change settings | ||
Security profile and firewall | ||
Virtual machine autostart configuration | ||
Host > Inventory | Modify cluster | |
Network | Assign network | |
Resource | Assign vApp to resource pool | |
Assign virtual machine to resource pool | ||
Sessions | Validate session | |
Tasks | Create task | |
Update task | ||
vApp | Add virtual machine | |
Assign resource pool | ||
Create | ||
Delete | ||
Import | ||
Power off | ||
Power on | ||
Rename | ||
Unregister | ||
vApp application configuration | ||
vApp instance configuration | ||
vApp managedBy configuration | ||
vApp resource configuration | ||
Virtual Machine > Configuration | Add existing disk | TempDatafile placement is required to restore an offsite backup. |
Add new disk | ||
Add or remove device | ||
Advanced | ||
Change CPU count | ||
Change resource | ||
Configure managedBy | ||
Extend virtual disk | ||
Memory | ||
Modify device settings | ||
Raw device | ||
Remove disk | ||
Rename | ||
Set annotation | ||
Settings | ||
Swapfile placement | ||
Upgrade virtual machine compatibility | ||
Virtual machine > Interaction | Power off | |
Power on | ||
Virtual machine > Inventory | Create from existing | |
Create new | ||
Move | ||
Register | ||
Remove | ||
Unregister |