{
  "vcfVersion": "9.1",
  "retrievedAt": "2026-09-15T14:51:54.031666+00:00",
  "source": "https://ports.broadcom.com/",
  "apiBase": "https://ports.esp.spespg1.vmw.saas.broadcom.com/manage/view/v1/",
  "versionId": "6a02e78a1809eae1a581f675",
  "products": [
    {
      "id": "6a02e5214e349d6d9c17240d",
      "name": "ESX",
      "category": 1,
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ],
      "rowCount": 91
    },
    {
      "id": "695f68c48f450aef4863a665",
      "name": "vCenter",
      "category": 1,
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ],
      "rowCount": 171
    },
    {
      "id": "6a02e294eccee231013d6d15",
      "name": "NSX",
      "category": 1,
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ],
      "rowCount": 62
    },
    {
      "id": "6a02e263eccee231013d6d14",
      "name": "vSAN",
      "category": 1,
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ],
      "rowCount": 58
    },
    {
      "id": "68591d4d48aeb10d5142cfc8",
      "name": "SDDC Manager",
      "category": 2,
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ],
      "rowCount": 106
    },
    {
      "id": "6a0306074e349d6d9c172422",
      "name": "VMware Private AI Services",
      "category": 3,
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ],
      "rowCount": 19
    },
    {
      "id": "68591d1548aeb10d5142cfc7",
      "name": "VCF Automation",
      "category": 3,
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ],
      "rowCount": 23
    },
    {
      "id": "6a0313621809eae1a581f68f",
      "name": "VCF Management Services",
      "category": 2,
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        },
        {
          "id": "6aa1286a4a973bfa11ce1650",
          "name": "9.1.1"
        }
      ],
      "rowCount": 27
    },
    {
      "id": "6859219a48aeb10d5142cfd0",
      "name": "Log Management",
      "category": 2,
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        },
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ],
      "rowCount": 72
    },
    {
      "id": "68591cf948aeb10d5142cfc6",
      "name": "VCF Operations",
      "category": 2,
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ],
      "rowCount": 91
    },
    {
      "id": "68591a8148aeb10d5142cfc5",
      "name": "VCF Operations HCX",
      "category": 2,
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ],
      "rowCount": 73
    },
    {
      "id": "6405a239c3f9fc6c492d9029",
      "name": "VCF Operations for Networks",
      "category": 2,
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ],
      "rowCount": 147
    },
    {
      "id": "6a045b144e349d6d9c172445",
      "name": "DSM Data Services",
      "category": 5,
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ],
      "rowCount": 59
    },
    {
      "id": "6a05a29e4020a053ebfe0770",
      "name": "VMware vDefend",
      "category": 5,
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        },
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ],
      "rowCount": 99
    },
    {
      "id": "6a05a3864020a053ebfe0771",
      "name": "Avi Load Balancer",
      "category": 5,
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ],
      "rowCount": 32
    },
    {
      "id": "6a06b6a41809eae1a581f6ac",
      "name": "vSphere Replication",
      "category": 5,
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ],
      "rowCount": 14
    },
    {
      "id": "6a06c43a1809eae1a581f6ad",
      "name": "Protection and Recovery Service for VCF Automation",
      "category": 5,
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ],
      "rowCount": 6
    },
    {
      "id": "6a06c6584e349d6d9c172452",
      "name": "Protection and Recovery",
      "category": 5,
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ],
      "rowCount": 17
    },
    {
      "id": "6a06c5a81809eae1a581f6af",
      "name": "VMware Live Recovery cloud",
      "category": 5,
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ],
      "rowCount": 16
    },
    {
      "id": "698e2e44906bdda1d154fa6a",
      "name": "Identity Broker",
      "category": 2,
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ],
      "rowCount": 26
    }
  ],
  "rows": [
    {
      "id": "6a02fd434aec70d0faf927d4",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "SSH",
      "serviceDescription": "Admin SSH into ESX host. Service disabled by default; IP-restricted when enabled.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd434aec70d0faf927d5",
      "port": "123",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization. Required for vSAN, certificate validity, and Kerberos.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd434aec70d0faf927d6",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "Host Client / API",
      "serviceDescription": "VMware Host Client and ESX management API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd434aec70d0faf927d7",
      "port": "443",
      "protocol": "TCP",
      "source": "Administration Systems Requiring VM Console Access",
      "destination": "ESX Management IP addresses",
      "purpose": "VM Console",
      "serviceDescription": "VM console access via vSphere Client or VMRC version 11 or later.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd434aec70d0faf927d8",
      "port": "443",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter Config",
      "serviceDescription": "ESX to vCenter for configuration sync and management.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd434aec70d0faf927d9",
      "port": "443",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Software Depot",
      "purpose": "Updates",
      "serviceDescription": "ESX to VCF software depot for image and patch downloads. Reached directly or through a customer proxy.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd434aec70d0faf927da",
      "port": "902",
      "protocol": "TCP",
      "source": "Backup Servers",
      "destination": "ESX Management IP addresses",
      "purpose": "NFC Backup",
      "serviceDescription": "NFC/NBD transfers between ESX and backup servers.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927db",
      "port": "902",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "Content Library",
      "serviceDescription": "NFC transfers between ESX hosts for Content Library.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927dc",
      "port": "902",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Remote ESX Management IP addresses",
      "purpose": "Cross-vCenter vMotion NFC",
      "serviceDescription": "NFC for advanced cross-vCenter vMotion to remote ESX hosts.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927dd",
      "port": "1443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "vSAN SPS",
      "serviceDescription": "vSAN Storage Policy Service. vCenter vmware-sps enforces storage policies and health.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927de",
      "port": "8000",
      "protocol": "TCP",
      "source": "ESX vMotion IP addresses",
      "destination": "ESX vMotion IP addresses",
      "purpose": "vMotion",
      "serviceDescription": "Live VM migration. vCenter orchestrates; ESX hosts connect peer-to-peer.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927df",
      "port": "8000",
      "protocol": "TCP",
      "source": "ESX vMotion IP addresses",
      "destination": "Remote ESX vMotion IP addresses",
      "purpose": "Cross-vCenter vMotion",
      "serviceDescription": "Advanced cross-vCenter vMotion to remote ESX hosts.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e0",
      "port": "8182",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere HA",
      "serviceDescription": "vSphere HA inter-host heartbeats and failover detection (Fault Domain Manager). Not the same as vCenter Server High Availability.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e1",
      "port": "8182",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere HA",
      "serviceDescription": "vSphere HA inter-host heartbeats and failover detection (Fault Domain Manager). Not the same as vCenter Server High Availability.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e2",
      "port": "8100",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere FT",
      "serviceDescription": "vSphere Fault Tolerance state synchronization (FT logging) between primary and secondary VM pairs. Uses the management VMkernel by default; a dedicated FT VMkernel interface can be configured.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e3",
      "port": "8100",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere FT",
      "serviceDescription": "vSphere Fault Tolerance state synchronization (FT logging) between primary and secondary VM pairs. Uses the management VMkernel by default; a dedicated FT VMkernel interface can be configured.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e4",
      "port": "8200",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere FT",
      "serviceDescription": "vSphere Fault Tolerance state synchronization (FT logging) between primary and secondary VM pairs. Uses the management VMkernel by default; a dedicated FT VMkernel interface can be configured.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e5",
      "port": "8200",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere FT",
      "serviceDescription": "vSphere Fault Tolerance state synchronization (FT logging) between primary and secondary VM pairs. Uses the management VMkernel by default; a dedicated FT VMkernel interface can be configured.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e6",
      "port": "8300",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere FT",
      "serviceDescription": "vSphere Fault Tolerance state synchronization (FT logging) between primary and secondary VM pairs. Uses the management VMkernel by default; a dedicated FT VMkernel interface can be configured.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e7",
      "port": "8300",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere FT",
      "serviceDescription": "vSphere Fault Tolerance state synchronization (FT logging) between primary and secondary VM pairs. Uses the management VMkernel by default; a dedicated FT VMkernel interface can be configured.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd444aec70d0faf927e8",
      "port": "9080",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "IO Filter",
      "serviceDescription": "vSphere I/O Filters. vCenter to ESX for filter framework communication, used by vSphere Replication and other storage integrations.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927e9",
      "port": "31031",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "vSphere Replication",
      "serviceDescription": "Host-Based Replication (HBR) data path. ESX sends VM replication data to the vSphere Replication target appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927ea",
      "port": "44046",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "vSphere Replication (Encrypted)",
      "serviceDescription": "Host-Based Replication (HBR) data path with in-flight encryption. Used when encrypted replication is configured; replaces 31031 for those VMs.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927eb",
      "port": "1492",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "VCF Live Cyber Recovery Connector address",
      "purpose": "VCF Live Cyber Recovery",
      "serviceDescription": "VCF Live Cyber Recovery data replication. The vltd transport on ESX sends replicated data to the VCF Live Cyber Recovery Connector using Lightweight Delta (LWD).",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927ec",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the management network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927ed",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the management network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927ee",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the management network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927ef",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the management network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f0",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between admin workstations and ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f1",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between admin workstations and ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f2",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between admin workstations and ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f3",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between admin workstations and ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f4",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "ESX vMotion IP addresses",
      "destination": "ESX vMotion IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the vMotion network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f5",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "ESX vMotion IP addresses",
      "destination": "ESX vMotion IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the vMotion network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd454aec70d0faf927f6",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "ESX vMotion IP addresses",
      "destination": "ESX vMotion IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the vMotion network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927f7",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "ESX vMotion IP addresses",
      "destination": "ESX vMotion IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts on the vMotion network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927f8",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts and the vSphere Replication appliance.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927f9",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts and the vSphere Replication appliance.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927fa",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts and the vSphere Replication appliance.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927fb",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "ESX Management IP addresses",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between ESX hosts and the vSphere Replication appliance.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927fc",
      "port": "9",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - DPM",
      "serviceDescription": "Wake-on-LAN for Dynamic Power Management.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927fd",
      "port": "53",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "DNS Resolvers",
      "purpose": "vSphere - Base",
      "serviceDescription": "DNS Client.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927fe",
      "port": "53",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "DNS Resolvers",
      "purpose": "vSphere - Base",
      "serviceDescription": "DNS Client.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf927ff",
      "port": "53",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf92800",
      "port": "53",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf92801",
      "port": "67",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "DHCPv4 Server",
      "purpose": "vSphere - DHCPv4",
      "serviceDescription": "DHCPv4 client - DHCPDISCOVER, DHCPREQUEST.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf92802",
      "port": "68",
      "protocol": "UDP",
      "source": "DHCPv4 Server",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - DHCPv4",
      "serviceDescription": "DHCPv4 client - DHCPOFFER, DHCPACK.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf92803",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - Base",
      "serviceDescription": "VMware Host Client - Redirect requests from HTTP to HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf92804",
      "port": "88",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd464aec70d0faf92805",
      "port": "88",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92806",
      "port": "88",
      "protocol": "TCP",
      "source": "Microsoft Active Directory Domain Controllers",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92807",
      "port": "88",
      "protocol": "UDP",
      "source": "Microsoft Active Directory Domain Controllers",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92808",
      "port": "111",
      "protocol": "TCP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - RPC Portmapper.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92809",
      "port": "111",
      "protocol": "UDP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - RPC Portmapper.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf9280a",
      "port": "135",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf9280b",
      "port": "161",
      "protocol": "UDP",
      "source": "SNMP Management System",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - SNMP",
      "serviceDescription": "SNMP access for monitoring and management.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf9280c",
      "port": "319",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "Precision Time Protocol Servers (224.0.1.129)",
      "purpose": "vSphere - PTP",
      "serviceDescription": "Precision Time Protocol - high resolution timekeeping for ESX and workloads.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf9280d",
      "port": "320",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "Precision Time Protocol Servers (224.0.1.129)",
      "purpose": "vSphere - PTP",
      "serviceDescription": "Precision Time Protocol - high resolution timekeeping for ESX and workloads.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf9280e",
      "port": "389",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf9280f",
      "port": "389",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92810",
      "port": "445",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92811",
      "port": "464",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92812",
      "port": "464",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92813",
      "port": "514",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "vSphere - Syslog",
      "serviceDescription": "Remote logging using syslog.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd474aec70d0faf92814",
      "port": "514",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "vSphere - Syslog",
      "serviceDescription": "Remote logging using syslog.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92815",
      "port": "546",
      "protocol": "UDP",
      "source": "DHCPv6 Server",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - DHCPv6",
      "serviceDescription": "DHCPv6 client - DHCPDISCOVER, DHCPREQUEST.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92816",
      "port": "547",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "DHCPv6 Server",
      "purpose": "vSphere - DHCPv6",
      "serviceDescription": "DHCPv6 client - DHCPOFFER, DHCPACK.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92817",
      "port": "635",
      "protocol": "TCP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - mountd. Note: This might be a dynamic port, check with your storage vendor for correct setting.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92818",
      "port": "635",
      "protocol": "UDP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - mountd. Note: This might be a dynamic port, check with your storage vendor for correct setting.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92819",
      "port": "636",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf9281a",
      "port": "1110",
      "protocol": "TCP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - statd. Note: This might be a dynamic port, check with your storage vendor for correct setting.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf9281b",
      "port": "1110",
      "protocol": "UDP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - statd. Note: This might be a dynamic port, check with your storage vendor for correct setting.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf9281c",
      "port": "1514",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "vSphere - Syslog",
      "serviceDescription": "Remote logging using syslog over TLS.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf9281d",
      "port": "2049",
      "protocol": "TCP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - Transport.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf9281e",
      "port": "2049",
      "protocol": "UDP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - Transport.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf9281f",
      "port": "2049",
      "protocol": "TCP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv4",
      "serviceDescription": "Core storage NFSv4 - Transport.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92820",
      "port": "2049",
      "protocol": "UDP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv4",
      "serviceDescription": "Core storage NFSv4 - Transport.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92821",
      "port": "3260",
      "protocol": "TCP",
      "source": "ESX iSCSI IP addresses",
      "destination": "iSCSI Storage Server",
      "purpose": "vSphere - iSCSI",
      "serviceDescription": "Core storage iSCSI Client.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd484aec70d0faf92822",
      "port": "3268",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92823",
      "port": "3269",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92824",
      "port": "4045",
      "protocol": "TCP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - lockd. Note: This might be a dynamic port, check with your storage vendor for correct setting.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92825",
      "port": "4045",
      "protocol": "UDP",
      "source": "ESX NFS IP addresses",
      "destination": "NFS Storage Server",
      "purpose": "vSphere - NFSv3",
      "serviceDescription": "Core storage NFSv3 - lockd. Note: This might be a dynamic port, check with your storage vendor for correct setting.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92826",
      "port": "4791",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "RDMA Storage Array",
      "purpose": "vSphere - RDMA/PVRDMA",
      "serviceDescription": "Support for RDMA-enabled Storage Arrays - Service Discovery.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92827",
      "port": "6999",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - NSX",
      "serviceDescription": "NSX Distributed Router.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92828",
      "port": "8301",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - dvSwitch",
      "serviceDescription": "Distributed Virtual Switch Communications.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf92829",
      "port": "8302",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere - dvSwitch",
      "serviceDescription": "Distributed Virtual Switch Communications.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf9282a",
      "port": "8443",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "VASA/VVOL Storage Array",
      "purpose": "vSphere - VASA/VVOL",
      "serviceDescription": "Core storage VVOL/VASA. Note: VASA providers and VVOL communication ports might vary between vendors.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf9282b",
      "port": "21451",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "RDMA Storage Array",
      "purpose": "vSphere - RDMA/PVRDMA",
      "serviceDescription": "Support for RDMA-enabled Storage Arrays - Service Discovery.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf9282c",
      "port": "21452",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "RDMA Storage Array",
      "purpose": "vSphere - RDMA/PVRDMA",
      "serviceDescription": "Support for RDMA-enabled Storage Arrays - Service Discovery.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf9282d",
      "port": "21455",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "RDMA Storage Array",
      "purpose": "vSphere - RDMA/PVRDMA",
      "serviceDescription": "Support for RDMA-enabled Storage Arrays - Data Traffic.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fd494aec70d0faf9282e",
      "port": "49152-65535",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSphere - IWA",
      "serviceDescription": "Active Directory Connectivity using Integrated Windows Authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "ESX",
      "productId": "6a02e5214e349d6d9c17240d",
      "releases": [
        {
          "id": "6a02ea235887ef2531709973",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02f3284aec70d0faf92753",
      "port": "53",
      "protocol": "TCP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "DNS Resolvers",
      "purpose": "Supervisor",
      "serviceDescription": "Allow Supervisor Control Plane VMs to connect to management network nameservers.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f3284aec70d0faf92754",
      "port": "53",
      "protocol": "UDP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "DNS Resolvers",
      "purpose": "Supervisor",
      "serviceDescription": "Allow Supervisor Control Plane VMs to connect to management network nameservers.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f3284aec70d0faf92755",
      "port": "53",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose the CoreDNS server. CoreDNS is the DNS server for the Supervisor Kubernetes cluster in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f3294aec70d0faf92756",
      "port": "53",
      "protocol": "UDP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose CoreDNS Pods over UDP. This allows Image Fetcher to communicate and resolve DNS. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f3294aec70d0faf92757",
      "port": "53",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "DNS Resolvers",
      "purpose": "Supervisor",
      "serviceDescription": "Allow Supervisor ControlPlane VMs to relay/forward name lookups that are not Supervisor cluster-local to external workload nameservers.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f3294aec70d0faf92758",
      "port": "53",
      "protocol": "UDP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "DNS Resolvers",
      "purpose": "Supervisor",
      "serviceDescription": "Allow Supervisor ControlPlane VMs to relay/forward name lookups that are not Supervisor cluster-local to external workload nameservers.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32a4aec70d0faf9275e",
      "port": "2113",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose Prometheus metrics from vsphere-syncer container in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32a4aec70d0faf92761",
      "port": "5000",
      "protocol": "TCP",
      "source": "Load Balancer Data Plane Interface",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS access to the kubectl-plugin-service (to the reverse proxy to internal Docker Registry service).",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32a4aec70d0faf92762",
      "port": "5000",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Supervisor Control Plane Management Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS access to the kubectl-plugin-service (to the reverse proxy to internal Docker Registry service).",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf92763",
      "port": "5000",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Supervisor Control Plane Management Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Enable vCenter to automatically check for the presence of Supervisor Service container images that are bundled with the Supervisor's internal Docker registry.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf92764",
      "port": "6443",
      "protocol": "TCP",
      "source": "Load Balancer Data Plane Interface",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS access to the kube-apiserver. The kube-apiserver is the control plane server that manages the Supervisor Kubernetes Cluster.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf92765",
      "port": "6443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Supervisor Control Plane Management Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS access to the kube-apiserver. The kube-apiserver is the control plane server that manages the Supervisor Kubernetes Cluster.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf92766",
      "port": "8070",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose metrics server for kube-state-metrics. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf92768",
      "port": "8099",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Allow AppPlatform's masterproxy to talk with the tkgs-plugin backend server. The tkgs-plugin-service is responsible for serving up the Angular app to the vCenter UI as well as modifying k8s resources for configuring TKC creation.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf92769",
      "port": "8384",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose a health-check endpoint for liveness and health-check probes for the nsx-operator pod in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf9276c",
      "port": "9001",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for App Platform Operator in Supervisor. Webhook service is responsible for securing the resources on CPVM from modification by third-party supervisor service operators. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32b4aec70d0faf9276e",
      "port": "9441",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose a health-check endpoint for liveness and health-check probes for the CAPI webhook pod in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92770",
      "port": "9808",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "NTP",
      "serviceDescription": "Expose the CSI Liveness Probe Health Server. Sidecar of the CSI driver used for health monitoring in Supervisor.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92771",
      "port": "9844",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Expose HTTPS proxy for CAPI controller-manager. Performs RBAC authorization against the metrics service in CAPI controller-mananger in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92773",
      "port": "9846",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Expose HTTPS proxy for CAPW controller-manager. Performs RBAC authorization against the metrics service in CAPW in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92774",
      "port": "9848",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS proxy for VM Operator. Performs RBAC authorization against the metrics service in VM Operator. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92775",
      "port": "9851",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS proxy for NETOP. Performs RBAC authorization against the metrics service in NETOP in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92776",
      "port": "9855",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "HTTPS proxy for GCM state metrics service. Performs RBAC authorization against the state metrics service in GCM. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92777",
      "port": "9859",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS proxy for mobility-operator. Performs RBAC authorization against the metrics service in mobility-operator in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92778",
      "port": "9874",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for CAPI in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32c4aec70d0faf92779",
      "port": "9875",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for CABPK in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32d4aec70d0faf9277b",
      "port": "9879",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for CAPV in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32d4aec70d0faf9277c",
      "port": "9883",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for CNS-CSI in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32d4aec70d0faf9277f",
      "port": "9890",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for mobility-operator in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32d4aec70d0faf92781",
      "port": "9897",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for common storage quota management in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32d4aec70d0faf92782",
      "port": "9898",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for WCP Namespace Operator in Supervisor. Webhook service in WCP Namespace Operator is responsible for capturing Kubernetes API data related to WCP Namespace Operator resources. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32e4aec70d0faf92785",
      "port": "10250",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose the kubelet HTTP server. The kubelet helps register the Supervisor Control Plane Node VMs as nodes to the kube-apiserver in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32e4aec70d0faf92786",
      "port": "10250",
      "protocol": "TCP",
      "source": "Supervisor (internal/loopback)",
      "destination": "Supervisor (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Expose the kubelet HTTP server. The kubelet helps register the Supervisor Control Plane Node VMs as nodes to the kube-apiserver in Supervisor.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32e4aec70d0faf92787",
      "port": "10250",
      "protocol": "TCP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "Supervisor",
      "serviceDescription": "Expose Spherelet's kubelet HTTP server. Spherelets register themselves as worker nodes in Supervisor.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32e4aec70d0faf92788",
      "port": "10351",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Allow lifecycle prechecks initiated by vCenter on the management Network to Service operators on the Supervisor in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32e4aec70d0faf9278a",
      "port": "12002",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose Pinniped in Supervisor. Used for authentication to Kubernetes Cluster. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02f32f4aec70d0faf9278e",
      "port": "123",
      "protocol": "UDP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "NTP Server",
      "purpose": "-",
      "serviceDescription": "Time synchronization for the Supervisor control plane.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf9282f",
      "port": "21",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (FTP)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over FTP. vCenter initiates the transfer to the backup target.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf92830",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into the vCenter Server Appliance for CLI access. Service disabled by default; IP-restricted when enabled.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf92831",
      "port": "22",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (SCP/SFTP)",
      "serviceDescription": "Outbound SSH for File-Based Backup and Restore over SCP or SFTP.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf92832",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "HTTP redirect (envoy)",
      "serviceDescription": "HTTP redirect to HTTPS for the vSphere Client. Listener accepts the connection and issues a redirect to port 443.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf92833",
      "port": "123",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization. Required for vSphere certificate validity, Kerberos (when applicable), and consistent audit logs.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf92834",
      "port": "389",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "VCF SSO LDAP (vmdir)",
      "serviceDescription": "LDAP listener for VCF SSO directory replication and lookups between vCenter nodes (vmdir). Used by Enhanced Linked Mode partners and during initial join operations.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde64aec70d0faf92835",
      "port": "636",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "VCF SSO LDAPS (vmdir)",
      "serviceDescription": "LDAPS (LDAP over TLS) listener for VCF SSO directory replication and lookups between vCenter nodes. The TLS-encrypted variant of 389.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf92836",
      "port": "2012",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "VCF SSO replication (DCE/RPC)",
      "serviceDescription": "DCE/RPC port for VCF SSO directory (vmdir) replication between vCenter nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf92837",
      "port": "2014",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMCA API (DCE/RPC)",
      "serviceDescription": "DCE/RPC port for VMware Certificate Authority (VMCA) API access between vCenter nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf92838",
      "port": "2016",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMware Authentication Framework (DCE/RPC)",
      "serviceDescription": "DCE/RPC port used by the VMware Authentication Framework daemon between vCenter nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf92839",
      "port": "2020",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMAFD API (DCE/RPC, vmafd)",
      "serviceDescription": "DCE/RPC port for VMware Endpoint Certificate Store (VMAFD) API access between vCenter nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf9283a",
      "port": "7444",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "Secure Token Service (stsd)",
      "serviceDescription": "Secure Token Service (STS) endpoint for legacy vCenter Single Sign-On authentication. Deprecated but maintained for backwards compatibility.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf9283b",
      "port": "8083",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "Lifecycle Manager settings (settingsd)",
      "serviceDescription": "vSphere Lifecycle Manager (vLCM) configuration store (settingsd). vCenter pushes desired-state configuration to ESX hosts. Distinct from the 8084 SOAP API.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf9283c",
      "port": "5696",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Key Management Server addresses",
      "purpose": "KMIP (VM Encryption)",
      "serviceDescription": "KMIP-compatible access to a Standard Key Provider (Key Management Server) for VM Encryption and vTPM.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf9283d",
      "port": "445",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (SMB)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over SMB. vCenter initiates the transfer to the backup target.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf9283e",
      "port": "514",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog",
      "serviceDescription": "vCenter forwards its own logs over syslog (plaintext). Typical destination is VCF Operations for Logs. The TLS-encrypted variant is 1514.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf9283f",
      "port": "514",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog",
      "serviceDescription": "vCenter forwards its own logs over syslog (plaintext). Typical destination is VCF Operations for Logs. The TLS-encrypted variant is 1514.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde74aec70d0faf92840",
      "port": "161",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "SNMP Management System",
      "purpose": "SNMP traps",
      "serviceDescription": "SNMP trap output from vCenter to a customer SNMP management system.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92841",
      "port": "25",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Email Server",
      "purpose": "SMTP (alarms)",
      "serviceDescription": "SMTP for emailed vCenter alarms. Configurable in alarm action settings.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92842",
      "port": "587",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Email Server",
      "purpose": "SMTP submission (alarms)",
      "serviceDescription": "SMTP submission port with authentication for emailed vCenter alarms..",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92843",
      "port": "53",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from vCenter to configured DNS resolvers.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92844",
      "port": "53",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from vCenter to configured DNS resolvers.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92845",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and managed ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92846",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and managed ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92847",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and managed ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92848",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and managed ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf92849",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf9284a",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde84aec70d0faf9284b",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf9284c",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf9284d",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Enhanced Linked Mode Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and peer vCenter Servers in Enhanced Linked Mode.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf9284e",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Enhanced Linked Mode Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and peer vCenter Servers in Enhanced Linked Mode.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf9284f",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Enhanced Linked Mode Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and peer vCenter Servers in Enhanced Linked Mode.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92850",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "Enhanced Linked Mode Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and peer vCenter Servers in Enhanced Linked Mode.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92851",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "vCHA Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and vCenter HA peer nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92852",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "vCHA Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and vCenter HA peer nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92853",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "vCHA Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and vCenter HA peer nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92854",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "vCenter Server Management IP address",
      "destination": "vCHA Partner Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vCenter Server and vCenter HA peer nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92855",
      "port": "20222",
      "protocol": "TCP",
      "source": "vCHA Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCHA private SSH",
      "serviceDescription": "Private SSH between vCenter HA (VCHA) nodes over the Eth1 (vCHA private) network for cluster management and synchronization.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fde94aec70d0faf92856",
      "port": "18899",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "SPS Java remote debugging (sps)",
      "serviceDescription": "Storage Policy Based Management (SPS) Java remote debugging endpoint. Bound to loopback; not reachable from the network.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf92857",
      "port": "8182",
      "protocol": "TCP",
      "source": "vCHA Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCHA cluster (vcha)",
      "serviceDescription": "vCenter HA (VCHA) cluster election and operation traffic between the active, passive, and witness nodes. Distinct from the same port number on ESX, which is used by vSphere HA FDM.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf92858",
      "port": "8084",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "Lifecycle Manager SOAP API (updatemgr)",
      "serviceDescription": "Legacy SOAP API for vSphere Lifecycle Manager. Used by admin tooling for patch and image profile management.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf92859",
      "port": "9084",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "Lifecycle Manager repository (updatemgr)",
      "serviceDescription": "vSphere Lifecycle Manager (vLCM) web server used by ESX hosts to download patches and image bundles.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf9285a",
      "port": "9087",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "Lifecycle Manager secure repository",
      "serviceDescription": "Secure HTTPS variant of the vSphere Lifecycle Manager patch repository web server.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf9285b",
      "port": "7476",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMCA Manager (vmcamd)",
      "serviceDescription": "VMware Certificate Authority Manager (VMCAM) HTTPS endpoint for certificate management operations.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf9285c",
      "port": "6500",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "ESX Dump Collector (netdumper)",
      "serviceDescription": "ESX hosts send kernel core dumps to vCenter's ESX Dump Collector service when a host crashes. Opt-in; configured per host.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf9285d",
      "port": "6500",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "ESX Dump Collector (netdumper)",
      "serviceDescription": "ESX hosts send kernel core dumps to vCenter's ESX Dump Collector service when a host crashes. Opt-in; configured per host.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf9285e",
      "port": "6501",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "Auto Deploy data (rbd)",
      "serviceDescription": "ESX hosts in stateless (Auto Deploy) boot use this port to download images and configuration data from vCenter. Used only when Auto Deploy is in use.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf9285f",
      "port": "6502",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "Auto Deploy management (rbd)",
      "serviceDescription": "Auto Deploy management endpoint for configuration tasks such as defining rules and image profiles. Used only when Auto Deploy is in use.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf92860",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "VAMI (applmgmt)",
      "serviceDescription": "vCenter Server Appliance Management Interface (VAMI) HTTPS port for appliance administration, including patching, networking, and certificate management.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdea4aec70d0faf92861",
      "port": "5432",
      "protocol": "TCP",
      "source": "vCHA Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "PostgreSQL replication (postgres)",
      "serviceDescription": "PostgreSQL database replication between vCenter Server nodes for vCenter HA (VCHA). Required between active, passive, and witness nodes during VCHA replication and during vCenter upgrades.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92862",
      "port": "1514",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog over TLS",
      "serviceDescription": "vCenter forwards its own logs to a central syslog server using syslog over TLS. Typical destination is VCF Operations for Logs.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92863",
      "port": "902",
      "protocol": "TCP/UDP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "ESX heartbeats",
      "serviceDescription": "Receives regular heartbeats from managed ESX hosts.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92864",
      "port": "67",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "DHCPv4 Server",
      "purpose": "DHCPv4",
      "serviceDescription": "DHCPv4 client requests from vCenter to the DHCP server (DHCPDISCOVER, DHCPREQUEST).",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92865",
      "port": "68",
      "protocol": "UDP",
      "source": "DHCPv4 Server",
      "destination": "vCenter Server Management IP address",
      "purpose": "DHCPv4",
      "serviceDescription": "DHCPv4 server replies to vCenter (DHCPOFFER, DHCPACK).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92866",
      "port": "547",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "DHCPv6 Server",
      "purpose": "DHCPv6",
      "serviceDescription": "DHCPv6 client requests from vCenter to the DHCP server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92867",
      "port": "546",
      "protocol": "UDP",
      "source": "DHCPv6 Server",
      "destination": "vCenter Server Management IP address",
      "purpose": "DHCPv6",
      "serviceDescription": "DHCPv6 server replies to vCenter.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92868",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vCenter Server Management IP address",
      "purpose": "vSphere Client / API (envoy)",
      "serviceDescription": "Primary HTTPS port for the vSphere Client, vSphere APIs, and third-party management tools.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf92869",
      "port": "443",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "ESX management",
      "serviceDescription": "ESX hosts connect to vCenter for management and config sync.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf9286a",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ESX management",
      "serviceDescription": "vCenter connects to ESX hosts for management operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf9286b",
      "port": "443",
      "protocol": "TCP",
      "source": "Enhanced Linked Mode Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "Enhanced Linked Mode",
      "serviceDescription": "Peer vCenter Server connection for Enhanced Linked Mode (ELM) replication and inventory queries.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdeb4aec70d0faf9286c",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "NSX Manager",
      "purpose": "NSX integration",
      "serviceDescription": "vCenter integration with NSX Manager.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf9286d",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Operations Management IP address",
      "purpose": "VCF Operations integration",
      "serviceDescription": "vCenter integration with VCF Operations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf9286e",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "VCF Operations for Logs integration",
      "serviceDescription": "vCenter integration with VCF Operations for Logs.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf9286f",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "vSphere Replication Target Management IP address",
      "purpose": "vSphere Replication integration",
      "serviceDescription": "vCenter management-plane integration with the vSphere Replication appliance.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92870",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VASA/VVOL Storage Array",
      "purpose": "VASA/VVOL",
      "serviceDescription": "vCenter to VASA provider for VVOL storage. Some VASA providers use 8443 or a vendor-specific port instead of 443; consult the storage vendor's documentation.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92871",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Hardware Support Manager IP Address",
      "purpose": "Hardware Support Manager",
      "serviceDescription": "vCenter to hardware support tools such as Dell OMIVV or HPE iLO Amplifier.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92872",
      "port": "443",
      "protocol": "TCP",
      "source": "vCHA Partner Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCHA management plane",
      "serviceDescription": "vCenter HA (VCHA) management-plane HTTPS traffic between active, passive, and witness nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92873",
      "port": "990",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (FTPS)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over FTPS (FTP with implicit TLS). vCenter initiates the transfer to the backup target.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92874",
      "port": "111",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS portmapper)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. RPC portmapper used to locate the mountd, statd, and lockd services on the backup target.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92875",
      "port": "111",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS portmapper)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. RPC portmapper used to locate the mountd, statd, and lockd services on the backup target.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92876",
      "port": "635",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS mountd)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFSv3 mountd. The actual mountd port can vary by server; 635 is the common default.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92877",
      "port": "635",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS mountd)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFSv3 mountd. The actual mountd port can vary by server; 635 is the common default.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdec4aec70d0faf92878",
      "port": "1110",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS statd)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFSv3 statd (status monitor) used for file-locking recovery. The actual statd port can vary by server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf92879",
      "port": "1110",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS statd)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFSv3 statd (status monitor) used for file-locking recovery. The actual statd port can vary by server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf9287a",
      "port": "2049",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS data)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFS transport (NFSv3 or NFSv4). Carries the bulk of the backup data.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf9287b",
      "port": "2049",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS data)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFS transport (NFSv3 or NFSv4). Carries the bulk of the backup data.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf9287c",
      "port": "4045",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS lockd)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFSv3 lockd (lock manager) used for byte-range file locks. The actual lockd port can vary by server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf9287d",
      "port": "4045",
      "protocol": "UDP",
      "source": "vCenter Server Management IP address",
      "destination": "FBBR Target Address",
      "purpose": "FBBR (NFS lockd)",
      "serviceDescription": "vCenter Server File-Based Backup and Restore (FBBR) over NFS. NFSv3 lockd (lock manager) used for byte-range file locks. The actual lockd port can vary by server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf9287e",
      "port": "69",
      "protocol": "UDP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Default TFTP port.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf9287f",
      "port": "4000",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Port for Sync as a Service Used for Sync as a Service implementation.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf92880",
      "port": "4001",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Port for Sync as a Service Used for Sync as a Service implementation.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fded4aec70d0faf92881",
      "port": "4002",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "gRPC port for Certificate management service for sync-as-a-service GRPC for SyncAAS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdee4aec70d0faf92882",
      "port": "4004",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Port for Sync as a Service Used for Sync as a Service implementation.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdee4aec70d0faf92883",
      "port": "4005",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Port for Sync as a Service Integration Used for Sync as a Service implementation.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdee4aec70d0faf92884",
      "port": "9085",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Jetty server port Static page that gives the status of updatemgr serivce - Healthy/unhealthy; Allow vSphere UI to download and host VUM UI local plugin; Allow vSphere UI to download and host VUM UI remote plugin.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdee4aec70d0faf92885",
      "port": "10112",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "CDS service endpoints CDS service root path.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdef4aec70d0faf92886",
      "port": "10114",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Endpoint for the access control service managing tenants, access tokens and OIDC endpoints ACS service root path; Manage tenants; CRUD operations on oauth2 clients for a given tenant; OAuth 2.0 flow authorize endpoint; OAuth 2.0 endpoint to get access token; OAuth 2.0 endpoint to revoke access token; Endpoint to fetch the OIDC Configuration; Endpoint to return JWT with claims; OIDC Logout.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdef4aec70d0faf92887",
      "port": "10116",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "SAAS service endpoints SAAS service root path.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdef4aec70d0faf92888",
      "port": "10121",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Health Check and Readiness Endpoints (Deprecated) Health check root path; (Deprecated) Endpoints returns true when all services are up; (Deprecated) Endpoints returns true when all services are ready to accept requests; Health check root path; Endpoints returns true when all services are up; Endpoints returns true when all services are.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdef4aec70d0faf92889",
      "port": "10125",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "UI service endpoints (Deprecated) Login page for the AD over LDAP vIDB feature; Login page for the AD over LDAP vIDB feature; Landing page for the VCF SSO user API Tokens.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf9288a",
      "port": "12080",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Internal port for the license service endpoints vAPI for the license service subscription functionality; vAPI for the license service subscription functionality; vAPI for the license service subscription functionality; vmodl1 API for the license service; VMODL1 impl of \"phonehome\" namespace - set/get CEIP; Read only endpoint for determining licen.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf9288b",
      "port": "13129",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "JMX port for certificatemanagement. Used by observability JMX handler used by observability.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf9288c",
      "port": "13131",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "JMX port for certificateauthority. Used by observability JMX handler used by observability.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf9288d",
      "port": "13135",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "JMX port for topologysvc. Used by observability JMX handler used by observability.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf9288e",
      "port": "13136",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "JMX Remote Connector JMX is enabled for the needs of Cloud Observability.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf9288f",
      "port": "13137",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "JMX remote connector JMX is enabled for the needs of Cloud Observability.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf92890",
      "port": "13138",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "JMX remote connector - RMI registry Embedded JVM handler.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf92891",
      "port": "13140",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Internal JMX management port of vpxd-svcs Embedded JVM handler.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf92892",
      "port": "13142",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Internal JMX management port of VSM Embedded JVM handler.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf04aec70d0faf92893",
      "port": "13144",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Internal JMX management port of vsphere-ui Embedded JVM handler.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf92894",
      "port": "13180",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Vstats vapi endpoint.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf92895",
      "port": "15080",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Internal port for the analytics service APIs An endpoint for working with Skyline Health; Sets or gets the CEIP flag; Sets or gets the CEIP flag; Get the state of the CEIP flag; vMon health status endpoint; Returns the analytics localization resource bundle jar file; Get Push telemetry level for specific collector on production.; Get Push tele.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf92896",
      "port": "16666",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Content Library Service port VAPI endpoint for CL Service; CL Service's health end point.; Endpoint used for streaming CL Service's support bundles.; Endpoint used by CL to upload and download, CL Transfer Service.; CL VCSP Protocol support; Static endpoint of a file in CL, used to download file content.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf92897",
      "port": "18900",
      "protocol": "TCP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "jmx endpoint for sps sps endpoint for jmx local connector - RMI registry.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf92898",
      "port": "36904",
      "protocol": "UDP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Ephemeral / dynamically assigned UDP socket opened by vsanvcmgmtd. Not a fixed listener; bound to a random high port at process start. No customer firewall opening required.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf92899",
      "port": "37618",
      "protocol": "UDP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Ephemeral / dynamically assigned UDP socket opened by java. Not a fixed listener; bound to a random high port at process start. No customer firewall opening required.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf9289a",
      "port": "48848",
      "protocol": "UDP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Ephemeral / dynamically assigned UDP socket opened by vpxd. Not a fixed listener; bound to a random high port at process start. No customer firewall opening required.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf9289b",
      "port": "54647",
      "protocol": "UDP",
      "source": "vCenter Server (internal/loopback)",
      "destination": "vCenter Server (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Ephemeral / dynamically assigned UDP socket opened by java. Not a fixed listener; bound to a random high port at process start. No customer firewall opening required.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf14aec70d0faf9289c",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Supervisor Control Plane Management Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose SSH access to Supervisor Control Plane VM in Supervisor.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928a3",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Supervisor Control Plane Management Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTP access to the kubectl-plugin-service (to the kubectl-plugin download page).",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928a4",
      "port": "80",
      "protocol": "TCP",
      "source": "Load Balancer Data Plane Interface",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTP access to the kubectl-plugin-service (to the kubectl-plugin download page).",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928a5",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Supervisor Control Plane Management Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS access to the kubectl-plugin-service (to the kubectl-plugin download page).",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928a6",
      "port": "443",
      "protocol": "TCP",
      "source": "Load Balancer Data Plane Interface",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS access to the kubectl-plugin-service (to the kubectl-plugin download page).",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928a7",
      "port": "2112",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose Prometheus metrics from vsphere-csi-controller container in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928a9",
      "port": "2379",
      "protocol": "TCP",
      "source": "Supervisor (internal/loopback)",
      "destination": "Supervisor (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Expose the etcd server, etcd is a distributed key-value store integral in storing state for the Kubernetes control plane.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf24aec70d0faf928aa",
      "port": "2380",
      "protocol": "TCP",
      "source": "Supervisor (internal/loopback)",
      "destination": "Supervisor (internal/loopback)",
      "purpose": "Supervisor",
      "serviceDescription": "Expose the etcd server, etcd is a distributed key-value store integral in storing state for the Kubernetes control plane.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf34aec70d0faf928b1",
      "port": "8093",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose metrics server for nsx-operator. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf34aec70d0faf928b5",
      "port": "8445",
      "protocol": "TCP",
      "source": "Supervisor LoadBalancer Transit Network",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose PROXY PROTOCOL-enabled HTTPS access to the kube-apiserver. The kube-apiserver is the control plane server that manages the Supervisor Kubernetes Cluster. Only used if PROXY PROTOCOL is enabled for the Supervisor.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf34aec70d0faf928b7",
      "port": "9440",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose a health-check endpoint for liveness and health-check probes for the CAPI controller-manager pod in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf44aec70d0faf928bc",
      "port": "9845",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Expose HTTPS proxy for CABPK controller-manager. Performs RBAC authorization against the metrics service in CABPK controller-manager in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf44aec70d0faf928c4",
      "port": "9878",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Webhook service in VM Operator, responsible for capturing Kubernetes API data related to VM Operator CRDs. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf54aec70d0faf928c7",
      "port": "9886",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "-",
      "serviceDescription": "Expose webhook service for Velero Carvel Package velero-vsphere operator in Supervisor. Network traffic is within the cluster.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf54aec70d0faf928c8",
      "port": "9889",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "-",
      "serviceDescription": "Expose the Metrics server for WCP Observability Operator.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf54aec70d0faf928ca",
      "port": "9891",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "-",
      "serviceDescription": "Expose webhook service for WCP Observability Operator in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf54aec70d0faf928cd",
      "port": "9900-9909",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose UI plugin proxy endpoint for UI backend communication for App Platform in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf54aec70d0faf928ce",
      "port": "9946",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose HTTPS proxy for CAPW webhook. Performs RBAC authorization against the metrics service in CAPW webhook in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf64aec70d0faf928d5",
      "port": "18310",
      "protocol": "TCP",
      "source": "Supervisor Primary Workload Network CIDR",
      "destination": "Supervisor Control Plane Cluster Network IP address",
      "purpose": "Supervisor",
      "serviceDescription": "Expose webhook service for Tanzu Addons Controller in Supervisor. Network traffic is within the cluster network.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf64aec70d0faf928d8",
      "port": "123",
      "protocol": "UDP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "NTP Server",
      "purpose": "-",
      "serviceDescription": "Time synchronization for the Supervisor control plane.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        },
        {
          "id": "6a991a470a0f8afb34ca2edf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a02fdf64aec70d0faf928d9",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "Management Workstations",
      "purpose": "-",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Supervisor control plane and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf64aec70d0faf928da",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "Management Workstations",
      "purpose": "-",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Supervisor control plane and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf64aec70d0faf928db",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "Management Workstations",
      "purpose": "-",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Supervisor control plane and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a02fdf64aec70d0faf928dc",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "Supervisor Control Plane Management Network IP address",
      "destination": "Management Workstations",
      "purpose": "-",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Supervisor control plane and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a035ff9c2b516e599a35d23",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "License Server Management IP address",
      "purpose": "License management (HTTPS)",
      "serviceDescription": "License synchronization with vCenter",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vCenter",
      "productId": "695f68c48f450aef4863a665",
      "releases": [
        {
          "id": "6a02ee2c4aec70d0faf926e4",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656029044725e5fb7c2fa",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "NSX Manager",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into NSX Manager. Service disabled by default.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656029044725e5fb7c2fb",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "NSX Edge nodes",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into NSX Edge nodes. Service disabled by default.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656029044725e5fb7c2fc",
      "port": "123",
      "protocol": "UDP",
      "source": "NSX Manager",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656029044725e5fb7c2fd",
      "port": "123",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for NSX Edge nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656029044725e5fb7c2fe",
      "port": "389",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "NSX Manager LDAP queries to Active Directory for user lookups and authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656029044725e5fb7c2ff",
      "port": "636",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "NSX Manager LDAPS (LDAP over TLS) queries to Active Directory. TLS-encrypted variant of 389.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c300",
      "port": "6514",
      "protocol": "TCP",
      "source": "Host Transport Node",
      "destination": "Syslog Servers",
      "purpose": "Syslog over TLS",
      "serviceDescription": "TLS-encrypted syslog export from NSX host transport nodes (ESX hosts running NSX) to a syslog or SIEM destination.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c301",
      "port": "514",
      "protocol": "TCP",
      "source": "Host Transport Node",
      "destination": "Syslog Servers",
      "purpose": "Syslog (plaintext)",
      "serviceDescription": "Plaintext syslog export from NSX host transport nodes. The TLS-encrypted variant is 6514.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c302",
      "port": "514",
      "protocol": "UDP",
      "source": "Host Transport Node",
      "destination": "Syslog Servers",
      "purpose": "Syslog (plaintext)",
      "serviceDescription": "Plaintext syslog export from NSX host transport nodes. The TLS-encrypted variant is 6514.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c303",
      "port": "53",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from NSX Manager to configured DNS resolvers.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c304",
      "port": "53",
      "protocol": "UDP",
      "source": "NSX Manager",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from NSX Manager to configured DNS resolvers.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c305",
      "port": "53",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from NSX Edge nodes to configured DNS resolvers.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c306",
      "port": "53",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from NSX Edge nodes to configured DNS resolvers.",
      "classification": "Outbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c307",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "NSX Manager",
      "purpose": "NSX UI / API (HTTPS)",
      "serviceDescription": "Primary HTTPS port for the NSX UI, REST APIs, and admin operations.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c308",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Manager",
      "purpose": "NSX Edge to Manager (HTTPS)",
      "serviceDescription": "NSX Edge nodes connect to NSX Manager over HTTPS for management and install-upgrade repository access.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c309",
      "port": "443",
      "protocol": "TCP",
      "source": "Host Transport Node",
      "destination": "NSX Manager",
      "purpose": "Host TN to Manager (HTTPS)",
      "serviceDescription": "Host transport nodes connect to NSX Manager over HTTPS for management and install-upgrade repository access.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c30a",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "NSX Manager",
      "purpose": "vCenter to NSX Manager",
      "serviceDescription": "vCenter Server integration with NSX Manager over HTTPS, including install-upgrade repository access.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c30b",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "NSX Manager cluster (HTTPS)",
      "serviceDescription": "Intra-cluster HTTPS between NSX Manager nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c30c",
      "port": "1234",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Manager",
      "purpose": "NSX RPC",
      "serviceDescription": "NSX RPC messaging from NSX Edge nodes to the NSX Manager control plane.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c30d",
      "port": "1235",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Manager",
      "purpose": "LCP to CCP (NSX RPC)",
      "serviceDescription": "Local Control Plane (LCP) on NSX Edge nodes to Central Control Plane (CCP) on NSX Manager.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c30e",
      "port": "1235",
      "protocol": "TCP",
      "source": "Host Transport Node",
      "destination": "NSX Manager",
      "purpose": "LCP to CCP (NSX RPC)",
      "serviceDescription": "Local Control Plane (LCP) on host transport nodes to Central Control Plane (CCP) on NSX Manager.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c30f",
      "port": "5671",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "NSX RPC (AMQP)",
      "serviceDescription": "AMQP-based NSX RPC messaging between NSX Manager cluster nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c310",
      "port": "5671",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Manager",
      "purpose": "NSX RPC (AMQP)",
      "serviceDescription": "AMQP-based NSX RPC messaging from NSX Edge nodes to NSX Manager.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656039044725e5fb7c311",
      "port": "5671",
      "protocol": "TCP",
      "source": "Host Transport Node",
      "destination": "NSX Manager",
      "purpose": "NSX RPC (AMQP)",
      "serviceDescription": "AMQP-based NSX RPC messaging from host transport nodes to NSX Manager.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c312",
      "port": "1236",
      "protocol": "TCP",
      "source": "NSX Local Manager",
      "destination": "NSX Global Manager",
      "purpose": "Federation Async Replicator",
      "serviceDescription": "Federation Async Replicator traffic between NSX Local Manager and NSX Global Manager across locations. Federation only.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c313",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Local Manager",
      "destination": "NSX Global Manager",
      "purpose": "Federation management plane (HTTPS)",
      "serviceDescription": "Federation management-plane HTTPS between NSX Local Manager and NSX Global Manager across locations. Federation only.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c314",
      "port": "50263",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "NSX Edge HA",
      "serviceDescription": "High-availability state synchronization between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c315",
      "port": "6666",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "NSX Edge local communication",
      "serviceDescription": "Local communication between NSX Edge node processes for control-plane operations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c316",
      "port": "2480",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "Nestdb (Edge state datastore)",
      "serviceDescription": "Nestdb internal state datastore replication between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c317",
      "port": "1167",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "NSX Edge DHCP lease HA sync",
      "serviceDescription": "DHCP lease information sync between NSX Edge nodes for HA, over a secure channel on the Edge management port.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c318",
      "port": "9000",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "NSX Manager distributed datastore",
      "serviceDescription": "Distributed datastore replication between NSX Manager cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c319",
      "port": "9040",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "NSX Manager distributed datastore",
      "serviceDescription": "Distributed datastore replication between NSX Manager cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c31a",
      "port": "500",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "External IPSEC Peers",
      "purpose": "IKE (IPSEC key exchange)",
      "serviceDescription": "Internet Key Exchange (IKE) for IPSEC VPN session establishment.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c31b",
      "port": "4500",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "External IPSEC Peers",
      "purpose": "IKE NAT-Traversal",
      "serviceDescription": "IKE NAT-Traversal for IPSEC VPN sessions traversing NAT.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c31c",
      "port": "N/A",
      "protocol": "ESP",
      "source": "NSX Edge nodes",
      "destination": "External IPSEC Peers",
      "purpose": "ESP (IPSEC payload)",
      "serviceDescription": "Encapsulating Security Payload, the IPSEC data path. Carries the encrypted VPN traffic. No transport port; IP protocol 50.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c31d",
      "port": "179",
      "protocol": "TCP",
      "source": "NSX Edge nodes",
      "destination": "External Routing Peers",
      "purpose": "BGP routing",
      "serviceDescription": "Border Gateway Protocol (BGP) session between NSX Edge nodes and external routers.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c31e",
      "port": "3784",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "External Routing Peers",
      "purpose": "BFD single-hop",
      "serviceDescription": "Bidirectional Forwarding Detection for directly connected routing peers. Provides sub-second failure detection for BGP and static routes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c31f",
      "port": "3785",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "External Routing Peers",
      "purpose": "BFD echo",
      "serviceDescription": "BFD echo function for directly connected routing peers.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c320",
      "port": "4784",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "External Routing Peers",
      "purpose": "BFD multi-hop",
      "serviceDescription": "Multi-hop BFD for routing peers more than one hop away (for example, multi-hop eBGP).",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c321",
      "port": "3784",
      "protocol": "UDP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "BFD between TEPs",
      "serviceDescription": "BFD between Tunnel Endpoint (TEP) IP addresses in the data plane, between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c322",
      "port": "3784",
      "protocol": "UDP",
      "source": "Host Transport Node",
      "destination": "NSX Edge nodes",
      "purpose": "BFD between TEPs",
      "serviceDescription": "BFD between Tunnel Endpoint (TEP) IP addresses in the data plane, between host transport nodes and NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c323",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "NSX Autonomous Edge Nodes",
      "purpose": "NSX Autonomous Edge UI / API",
      "serviceDescription": "HTTPS for the NSX Autonomous Edge management UI and API.",
      "classification": "Inbound",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656049044725e5fb7c324",
      "port": "6081",
      "protocol": "UDP",
      "source": "GENEVE RTEP",
      "destination": "GENEVE RTEP",
      "purpose": "Federation GENEVE RTEP",
      "serviceDescription": "GENEVE Remote Tunnel End Point (RTEP) for cross-location data-plane traffic between NSX Edge nodes in NSX Federation. Federation only.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c325",
      "port": "443",
      "protocol": "TCP",
      "source": "Antrea Interworking Pod",
      "destination": "NSX Manager",
      "purpose": "Antrea integration (HTTPS)",
      "serviceDescription": "HTTPS from the Antrea Interworking Pod (Kubernetes) to NSX Manager.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c326",
      "port": "1234",
      "protocol": "TCP",
      "source": "Antrea Interworking Pod",
      "destination": "NSX Manager",
      "purpose": "Antrea NSX-RPC",
      "serviceDescription": "NSX-RPC from the Antrea Interworking Pod to NSX Manager.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c327",
      "port": "1235",
      "protocol": "TCP",
      "source": "Antrea Interworking Pod",
      "destination": "NSX Manager",
      "purpose": "Antrea NSX-RPC",
      "serviceDescription": "NSX-RPC from the Antrea Interworking Pod to NSX Manager.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c328",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager nodes (cluster peers).",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c329",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager nodes (cluster peers).",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c32a",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager nodes (cluster peers).",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c32b",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager nodes (cluster peers).",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c32c",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c32d",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c32e",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c32f",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "NSX Manager",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Manager and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c330",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c331",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c332",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c333",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "NSX Edge nodes",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c334",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c335",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c336",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a1656059044725e5fb7c337",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "NSX Edge nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between NSX Edge nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-24T00:00:00Z",
      "product": "NSX",
      "productId": "6a02e294eccee231013d6d15",
      "releases": [
        {
          "id": "6a02fed95887ef25317099d0",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928eb",
      "port": "1564",
      "protocol": "TCP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN VDFS Data Path",
      "serviceDescription": "vSAN VDFS data path between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928ec",
      "port": "1565",
      "protocol": "TCP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN VDFS Proxy",
      "serviceDescription": "vSAN VDFS proxy between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928ed",
      "port": "2233",
      "protocol": "TCP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN RDT",
      "serviceDescription": "vSAN Reliable Datagram Transport. CLOM, LSOM, and DOM inter-node traffic on the vSAN VMkernel network.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928ee",
      "port": "5201",
      "protocol": "TCP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN Proactive Network Testing",
      "serviceDescription": "iperf-based proactive network testing between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928ef",
      "port": "5201",
      "protocol": "UDP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN Proactive Network Testing",
      "serviceDescription": "iperf-based proactive network testing between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f0",
      "port": "12321",
      "protocol": "UDP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN CMMDS",
      "serviceDescription": "vSAN Cluster Monitoring, Membership, and Directory Service heartbeat between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f1",
      "port": "12345",
      "protocol": "UDP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN CMMDS",
      "serviceDescription": "vSAN Cluster Monitoring, Membership, and Directory Service between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f2",
      "port": "12443",
      "protocol": "TCP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN Storage Transport",
      "serviceDescription": "vSAN Storage Transport between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f3",
      "port": "23451",
      "protocol": "UDP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN CMMDS",
      "serviceDescription": "vSAN Cluster Monitoring, Membership, and Directory Service between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f4",
      "port": "443",
      "protocol": "TCP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN inter-host HTTPS",
      "serviceDescription": "HTTPS endpoint tunnel for node-to-node management and monitoring operations between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f5",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "ICMP utility (vSAN cluster)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f6",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "ICMP utility (vSAN cluster)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302214aec70d0faf928f7",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "ICMP utility (vSAN cluster)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928f8",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "ESX vSAN IP addresses",
      "purpose": "ICMP utility (vSAN cluster)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928f9",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "vSAN Witness IP address",
      "purpose": "ICMP utility (Witness)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts and the Witness appliance. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928fa",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "vSAN Witness IP address",
      "purpose": "ICMP utility (Witness)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts and the Witness appliance. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928fb",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "vSAN Witness IP address",
      "purpose": "ICMP utility (Witness)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts and the Witness appliance. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928fc",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "ESX vSAN IP addresses",
      "destination": "vSAN Witness IP address",
      "purpose": "ICMP utility (Witness)",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery (Fragmentation Needed) between vSAN hosts and the Witness appliance. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928fd",
      "port": "5696",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Key Management Server addresses",
      "purpose": "KMIP (vSAN Encryption)",
      "serviceDescription": "KMIP-compatible access to a Standard Key Provider (KMS) for vSAN Encryption. Shares the KMS configuration with VM Encryption.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928fe",
      "port": "3260",
      "protocol": "TCP",
      "source": "vSAN iSCSI Clients",
      "destination": "vSAN iSCSI Target Service IP address",
      "purpose": "vSAN iSCSI Target Service",
      "serviceDescription": "Client access to the vSAN iSCSI Target Service. vSAN serves as an iSCSI target for external initiators.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf928ff",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Broadcom Telemetry Service",
      "purpose": "vSAN CEIP / PHM telemetry",
      "serviceDescription": "vSAN management service in vCenter sends CEIP telemetry to vcsa.telemetry.broadcom.com. vSAN Proactive Hardware Management (PHM) also contacts external HSM appliances for compliance checks via this endpoint.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92900",
      "port": "53",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "DNS Resolvers",
      "purpose": "vSAN File Service DNS",
      "serviceDescription": "DNS resolution for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92901",
      "port": "53",
      "protocol": "UDP",
      "source": "vSAN File Services IP Addresses",
      "destination": "DNS Resolvers",
      "purpose": "vSAN File Service DNS",
      "serviceDescription": "DNS resolution for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92902",
      "port": "123",
      "protocol": "UDP",
      "source": "vSAN File Services IP Addresses",
      "destination": "NTP Server",
      "purpose": "vSAN File Service NTP",
      "serviceDescription": "Time synchronization for the vSAN File Service appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92903",
      "port": "88",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service Kerberos (AD)",
      "serviceDescription": "Kerberos authentication to Active Directory for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92904",
      "port": "88",
      "protocol": "UDP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service Kerberos (AD)",
      "serviceDescription": "Kerberos authentication to Active Directory for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92905",
      "port": "135",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service RPC endpoint mapper (AD)",
      "serviceDescription": "RPC endpoint mapper used by Microsoft RPC services in the vSAN File Service AD integration. Connections continue on the dynamic RPC port range.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92906",
      "port": "389",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service LDAP (AD)",
      "serviceDescription": "LDAP queries to Active Directory for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92907",
      "port": "389",
      "protocol": "UDP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service LDAP (AD)",
      "serviceDescription": "LDAP queries to Active Directory for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92908",
      "port": "464",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service Kerberos password (AD)",
      "serviceDescription": "Kerberos password-change operations to Active Directory for the vSAN File Service.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302224aec70d0faf92909",
      "port": "636",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service LDAPS (AD)",
      "serviceDescription": "LDAPS (LDAP over TLS) queries to Active Directory for the vSAN File Service. TLS-encrypted variant of 389.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9290a",
      "port": "49152/65535",
      "protocol": "TCP",
      "source": "vSAN File Services IP Addresses",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "vSAN File Service RPC dynamic ports (AD)",
      "serviceDescription": "Dynamic RPC port range used by Microsoft RPC services in the vSAN File Service AD integration once the connection has been negotiated via port 135.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9290b",
      "port": "111",
      "protocol": "TCP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS portmapper",
      "serviceDescription": "RPC portmapper used by NFS clients to locate the mountd, statd, and lockd services on the vSAN File Service.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9290c",
      "port": "111",
      "protocol": "UDP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS portmapper",
      "serviceDescription": "RPC portmapper used by NFS clients to locate the mountd, statd, and lockd services on the vSAN File Service.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9290d",
      "port": "875",
      "protocol": "TCP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS rquotad",
      "serviceDescription": "NFS rquotad (quota daemon) reports user and group quota information to NFS clients.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9290e",
      "port": "2049",
      "protocol": "TCP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS data",
      "serviceDescription": "Primary NFS data transport. Handles both NFSv3 and NFSv4 traffic.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9290f",
      "port": "20048",
      "protocol": "TCP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS mountd",
      "serviceDescription": "NFS mountd handles NFSv3 mount requests from clients.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92910",
      "port": "27689",
      "protocol": "TCP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS nlockmgr",
      "serviceDescription": "NFS network lock manager (nlockmgr) handles byte-range file locks.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92911",
      "port": "32803",
      "protocol": "TCP",
      "source": "vSAN NFS Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service NFS statd",
      "serviceDescription": "NFS status monitor (statd) used for file-locking recovery.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92912",
      "port": "445",
      "protocol": "TCP",
      "source": "vSAN SMB Clients",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "vSAN File Service SMB",
      "serviceDescription": "SMB protocol for file sharing from vSAN File Service to Windows and other SMB clients.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92913",
      "port": "32032",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Remote ESX Management IP addresses",
      "purpose": "vSAN DP replication (host-to-host)",
      "serviceDescription": "vSAN Data Protection replication between local and remote ESX hosts.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92914",
      "port": "32032",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Remote vSAN Data Protection Appliance",
      "purpose": "vSAN DP replication (host-to-appliance)",
      "serviceDescription": "vSAN Data Protection replication from local ESX hosts to a remote vSAN Data Protection Appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92915",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vSAN Data Protection Appliance",
      "purpose": "vSAN DP UI / API (HTTPS)",
      "serviceDescription": "HTTPS port on the vSAN Data Protection Appliance for the vSphere Client UI and API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92916",
      "port": "443",
      "protocol": "TCP",
      "source": "vSAN Data Protection Appliance",
      "destination": "ESX Management IP addresses",
      "purpose": "vSAN DP to local ESX",
      "serviceDescription": "vSAN Data Protection Appliance to local ESX hosts over HTTPS for management operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92917",
      "port": "443",
      "protocol": "TCP",
      "source": "vSAN Data Protection Appliance",
      "destination": "vCenter Server Management IP address",
      "purpose": "vSAN DP to local vCenter",
      "serviceDescription": "vSAN Data Protection Appliance to the local vCenter Server over HTTPS.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92918",
      "port": "443",
      "protocol": "TCP",
      "source": "vSAN Data Protection Appliance",
      "destination": "Remote vCenter Server Management IP address",
      "purpose": "vSAN DP to remote vCenter",
      "serviceDescription": "vSAN Data Protection Appliance to a remote vCenter Server over HTTPS.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf92919",
      "port": "443",
      "protocol": "TCP",
      "source": "vSAN Data Protection Appliance",
      "destination": "Remote vSAN Data Protection Appliance",
      "purpose": "vSAN DP peer (source/remote)",
      "serviceDescription": "Source and remote vSAN Data Protection Appliance communication over HTTPS.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9291a",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "vSAN Data Protection Appliance",
      "purpose": "vSAN DP VAMI",
      "serviceDescription": "vSAN Data Protection Appliance Management Interface (VAMI) HTTPS port.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9291b",
      "port": "443",
      "protocol": "TCP",
      "source": "vSAN Witness IP address",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN Performance Service (Witness)",
      "serviceDescription": "HTTPS metrics collection between the vSAN Performance Service on the Witness appliance and data hosts. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302234aec70d0faf9291c",
      "port": "2233",
      "protocol": "TCP",
      "source": "vSAN Witness IP address",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN RDT (Witness)",
      "serviceDescription": "vSAN Reliable Datagram Transport between the Witness appliance and data hosts. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf9291d",
      "port": "12321",
      "protocol": "UDP",
      "source": "vSAN Witness IP address",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN CMMDS (Witness)",
      "serviceDescription": "vSAN Cluster Monitoring, Membership, and Directory Service between the Witness appliance and data hosts. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf9291e",
      "port": "12345",
      "protocol": "UDP",
      "source": "vSAN Witness IP address",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN CMMDS (Witness)",
      "serviceDescription": "vSAN Cluster Monitoring, Membership, and Directory Service between the Witness appliance and data hosts. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf9291f",
      "port": "12443",
      "protocol": "TCP",
      "source": "vSAN Witness IP address",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN Storage Transport (Witness)",
      "serviceDescription": "vSAN Storage Transport between the Witness appliance and data hosts. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf92920",
      "port": "23451",
      "protocol": "UDP",
      "source": "vSAN Witness IP address",
      "destination": "ESX vSAN IP addresses",
      "purpose": "vSAN CMMDS (Witness)",
      "serviceDescription": "vSAN Cluster Monitoring, Membership, and Directory Service between the Witness appliance and data hosts. Two-Node and Stretched Cluster deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf92921",
      "port": "9097",
      "protocol": "TCP",
      "source": "vSAN host (internal/loopback)",
      "destination": "vSAN host (internal/loopback)",
      "purpose": "-",
      "serviceDescription": "vSAN Management - vSAN Metrics REST Endpoint.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf92922",
      "port": "9096",
      "protocol": "TCP",
      "source": "vSAN host (internal/loopback)",
      "destination": "vSAN host (internal/loopback)",
      "purpose": "-",
      "serviceDescription": "Internal port for vSAN Management service backend VMODL HTTPS endpoint in ESX host.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf92923",
      "port": "9095",
      "protocol": "TCP",
      "source": "vSAN host (internal/loopback)",
      "destination": "vSAN host (internal/loopback)",
      "purpose": "-",
      "serviceDescription": "Internal port for vSAN Management service backend VMODL HTTPS tunnel endpoint in ESX host.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0302244aec70d0faf92924",
      "port": "8006",
      "protocol": "TCP",
      "source": "vSAN host (internal/loopback)",
      "destination": "vSAN host (internal/loopback)",
      "purpose": "-",
      "serviceDescription": "vSAN management service in vCenter handles management operations from clients.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "vSAN",
      "productId": "6a02e263eccee231013d6d14",
      "releases": [
        {
          "id": "6a02f53f4aec70d0faf92794",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303475887ef25317099d1",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "SDDC Manager Management IP address",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into SDDC Manager. Service disabled by default; IP-restricted when enabled.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303475887ef25317099d2",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Installer Management IP address",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into VCF Installer. Service disabled by default; IP-restricted when enabled.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303475887ef25317099d3",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "SDDC Manager Management IP address",
      "purpose": "SDDC Manager UI / API",
      "serviceDescription": "Primary HTTPS port for the SDDC Manager UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303475887ef25317099d4",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Installer Management IP address",
      "purpose": "VCF Installer UI / API",
      "serviceDescription": "Primary HTTPS port for the VCF Installer UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303475887ef25317099d5",
      "port": "53",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from SDDC Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099d6",
      "port": "53",
      "protocol": "UDP",
      "source": "SDDC Manager Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from SDDC Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099d7",
      "port": "123",
      "protocol": "UDP",
      "source": "SDDC Manager Management IP address",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for SDDC Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099d8",
      "port": "53",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099d9",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Installer Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099da",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Installer Management IP address",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099db",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "SSH (deployment)",
      "serviceDescription": "SSH from VCF Installer to ESX hosts during bring-up and lifecycle operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099dc",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "HTTPS to ESX",
      "serviceDescription": "HTTPS from VCF Installer to ESX hosts for management API operations during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099dd",
      "port": "8085",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "VCF Installer deployment API",
      "serviceDescription": "REST API between VCF Installer UI and ESX backend microservices during bring-up (replaces the excel-based bring-up method). Destination ESX is both the management and tenant ESX role.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099de",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "HTTPS to vCenter",
      "serviceDescription": "HTTPS from VCF Installer to vCenter Server during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099df",
      "port": "5480",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter VAMI",
      "serviceDescription": "VCF Installer to vCenter VAMI for appliance management during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099e0",
      "port": "7444",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter SSO (STS)",
      "serviceDescription": "VCF Installer to vCenter SSO for authentication during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099e1",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "NSX Manager",
      "purpose": "HTTPS to NSX Manager",
      "serviceDescription": "HTTPS from VCF Installer to NSX Manager during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099e2",
      "port": "67",
      "protocol": "UDP",
      "source": "VCF Installer Management IP address",
      "destination": "DHCPv4 Server",
      "purpose": "DHCP relay",
      "serviceDescription": "DHCP relay service on the VCF Installer embedded appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303485887ef25317099e3",
      "port": "68",
      "protocol": "UDP",
      "source": "VCF Installer Management IP address",
      "destination": "DHCPv4 Server",
      "purpose": "DHCP relay",
      "serviceDescription": "DHCP relay service on the VCF Installer embedded appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099e4",
      "port": "2049",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "vSAN File Services IP Addresses",
      "purpose": "NFS to vSAN File Services",
      "serviceDescription": "NFS from VCF Installer to vSAN File Services for bring-up file operations and backups.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099e5",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "Software Depot",
      "purpose": "Offline depot",
      "serviceDescription": "VCF Installer to offline depot or update repository for image and bundle access.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099e6",
      "port": "9443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "VCF Operations Fleet Manager Management IP address",
      "purpose": "Fleet Manager LCM",
      "serviceDescription": "VCF Installer to VCF Operations Fleet Manager for lifecycle and VCF Web UI operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099e7",
      "port": "135",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "RPC endpoint mapper (AD)",
      "serviceDescription": "RPC endpoint mapper used by VCF Installer when integrating with Active Directory.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099e8",
      "port": "389",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "LDAP queries to Active Directory from VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099e9",
      "port": "389",
      "protocol": "UDP",
      "source": "VCF Installer Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "LDAP queries to Active Directory from VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099ea",
      "port": "636",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "LDAPS queries to Active Directory from VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099eb",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "HTTPS to Supervisor",
      "serviceDescription": "HTTPS from VCF Installer to Supervisor (VKS / VMSP) cluster during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099ec",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "VCF Automation Management IP address",
      "purpose": "HTTPS to VCF Automation",
      "serviceDescription": "HTTPS from VCF Installer to VCF Automation during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099ed",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "VCF Operations for Networks Management IP address",
      "purpose": "HTTPS to VCF Ops for Networks",
      "serviceDescription": "HTTPS from VCF Installer to VCF Operations for Networks during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099ee",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "HTTPS to VCF Ops for Logs",
      "serviceDescription": "HTTPS from VCF Installer to VCF Operations for Logs during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099ef",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "VCF Operations Management IP address",
      "purpose": "HTTPS to VCF Operations",
      "serviceDescription": "HTTPS from VCF Installer to VCF Operations during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303495887ef25317099f0",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Identity Broker",
      "purpose": "SSH to VCF Identity Broker",
      "serviceDescription": "SSH from SDDC Manager to VCF Identity Broker for bring-up operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f1",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Identity Broker",
      "purpose": "HTTPS to VCF Identity Broker",
      "serviceDescription": "HTTPS API access from SDDC Manager to VCF Identity Broker.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f2",
      "port": "7444",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Identity Broker",
      "purpose": "SSO (STS) to VCF Identity Broker",
      "serviceDescription": "SDDC Manager SSO (STS) authentication via VCF Identity Broker.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f3",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Installer Management IP address",
      "purpose": "SSH to VCF Installer",
      "serviceDescription": "SSH from SDDC Manager to VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f4",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Installer Management IP address",
      "purpose": "HTTPS to VCF Installer",
      "serviceDescription": "HTTPS API access from SDDC Manager to VCF Installer.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f5",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "SSH to VCF Ops for Logs",
      "serviceDescription": "SSH from SDDC Manager to VCF Operations for Logs for management operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f6",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "HTTPS to VCF Ops for Logs",
      "serviceDescription": "HTTPS API access from SDDC Manager to VCF Operations for Logs.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f7",
      "port": "514",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog forward",
      "serviceDescription": "Syslog forwarding from SDDC Manager to VCF Operations for Logs.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f8",
      "port": "9000",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "VCF Ops for Logs ingestion (CFAPI)",
      "serviceDescription": "VCF Operations for Logs ingestion API (CFAPI) over plain HTTP. Used by SDDC Manager for log ingestion.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099f9",
      "port": "9543",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "VCF Ops for Logs management API",
      "serviceDescription": "VCF Operations for Logs management API used by SDDC Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099fa",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Automation Management IP address",
      "purpose": "SSH to VCF Automation",
      "serviceDescription": "SSH from SDDC Manager to VCF Automation for management operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099fb",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Automation Management IP address",
      "purpose": "HTTPS to VCF Automation",
      "serviceDescription": "HTTPS API access from SDDC Manager to VCF Automation.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099fc",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations Management IP address",
      "purpose": "SSH to VCF Operations",
      "serviceDescription": "SSH from SDDC Manager to VCF Operations for management operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099fd",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations Management IP address",
      "purpose": "HTTPS to VCF Operations",
      "serviceDescription": "HTTPS API access from SDDC Manager to VCF Operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034a5887ef25317099fe",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations Fleet Manager Management IP address",
      "purpose": "SSH to Fleet Manager",
      "serviceDescription": "SSH from SDDC Manager to VCF Operations Fleet Manager for deployment, troubleshooting, and file transfers.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef25317099ff",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "VCF Operations Fleet Manager Management IP address",
      "purpose": "HTTPS to Fleet Manager",
      "serviceDescription": "HTTPS API access between SDDC Manager and VCF Operations Fleet Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a00",
      "port": "8084",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "Lifecycle Manager SOAP API",
      "serviceDescription": "SDDC Manager to vCenter vSphere Lifecycle Manager SOAP API for image and patch management. Not used between vCenter and SDDC Manager when both are co-located.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a01",
      "port": "9084",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "Lifecycle Manager repository",
      "serviceDescription": "SDDC Manager to vCenter vSphere Lifecycle Manager patch repository.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a02",
      "port": "9087",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "Lifecycle Manager secure repository",
      "serviceDescription": "SDDC Manager to vCenter vSphere Lifecycle Manager secure patch repository.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a03",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "SSH to vCenter",
      "serviceDescription": "SSH from SDDC Manager to vCenter for initial deployment.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a04",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "HTTPS to vCenter",
      "serviceDescription": "HTTPS to vCenter Server SDK and API for certificate management, domain lifecycle, cluster operations, and health checks.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a05",
      "port": "5480",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter VAMI",
      "serviceDescription": "SDDC Manager to vCenter VAMI for appliance management operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a06",
      "port": "7444",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter SSO (STS)",
      "serviceDescription": "SDDC Manager to vCenter SSO for authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a07",
      "port": "22",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "SSH to ESX",
      "serviceDescription": "SSH from SDDC Manager to ESX hosts during bring-up and lifecycle operations (patching, upgrades).",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a08",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "HTTPS to ESX",
      "serviceDescription": "HTTPS API access from SDDC Manager to ESX hosts.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a09",
      "port": "902",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ESX bring-up",
      "serviceDescription": "Bring-up flow from SDDC Manager to ESX hosts. Listed on the Broadcom ports page; not typically active outside the initial deployment phase.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a0a",
      "port": "2049",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "NFS data to ESX",
      "serviceDescription": "NFS client file-system traffic from SDDC Manager to ESX hosts during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a0b",
      "port": "2049",
      "protocol": "UDP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "NFS data to ESX",
      "serviceDescription": "NFS client file-system traffic from SDDC Manager to ESX hosts during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034b5887ef2531709a0c",
      "port": "32767",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "NFS mountd to ESX",
      "serviceDescription": "NFS mountd traffic from SDDC Manager to ESX hosts during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a0d",
      "port": "32767",
      "protocol": "UDP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "NFS mountd to ESX",
      "serviceDescription": "NFS mountd traffic from SDDC Manager to ESX hosts during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a0e",
      "port": "32766",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "NFS lock recovery to ESX",
      "serviceDescription": "NFS lock-manager crash and recovery traffic from SDDC Manager to ESX hosts during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a0f",
      "port": "32766",
      "protocol": "UDP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "NFS lock recovery to ESX",
      "serviceDescription": "NFS lock-manager crash and recovery traffic from SDDC Manager to ESX hosts during bring-up.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a10",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "NSX Manager",
      "purpose": "HTTPS to NSX Manager",
      "serviceDescription": "HTTPS to NSX Manager for network lifecycle management, NSX configuration, transport nodes, and edge deployment.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a11",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and ESX hosts for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a12",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and ESX hosts for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a13",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and ESX hosts for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a14",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and ESX hosts for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a15",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and vCenter Servers for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a16",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and vCenter Servers for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a17",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and vCenter Servers for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a18",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and vCenter Servers for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034c5887ef2531709a19",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and NSX Manager for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a1a",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and NSX Manager for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a1b",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and NSX Manager for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a1c",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "SDDC Manager Management IP address",
      "destination": "NSX Manager",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between SDDC Manager and NSX Manager for IP reachability checks.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a1d",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "Broadcom Telemetry Service",
      "purpose": "Broadcom CEIP telemetry",
      "serviceDescription": "Broadcom CEIP telemetry phone-home (scapi.telemetry.broadcom.com). Disabled if CEIP is opted out.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a1e",
      "port": "4505",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "Salt minion publish",
      "serviceDescription": "Salt minion subscribes to Salt master publish port to receive config commands and state executions. Used by the VMSP / Supervisor integration. Absent in 9.0.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a1f",
      "port": "4506",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "Salt minion return",
      "serviceDescription": "Salt minion returns execution results to the Salt master return port. Used by the VMSP / Supervisor integration. Absent in 9.0.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a20",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "HTTPS to Supervisor",
      "serviceDescription": "HTTPS from SDDC Manager to the Supervisor (VMSP / VKS) cluster.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034d5887ef2531709a21",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "Broadcom public URLs",
      "purpose": "Broadcom public URL access",
      "serviceDescription": "HTTPS to Broadcom-hosted public URLs for SDDC Manager (depots, support, KB). Destination list maintained in Broadcom KB 327186.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a22",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Installer Management IP address",
      "destination": "Broadcom public URLs",
      "purpose": "Broadcom public URL access",
      "serviceDescription": "HTTPS to Broadcom-hosted public URLs for VCF Installer (depots, support, KB). Destination list maintained in Broadcom KB.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a23",
      "port": "80",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "Internal nginx reverse proxy ,  loopback only (127.0.0.1 / [",
      "serviceDescription": "Internal nginx reverse proxy ,  loopback only (127.0.0.1 / [::1])",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a24",
      "port": "5432",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "Internal PostgreSQL DB used by all microservices",
      "serviceDescription": "Internal PostgreSQL DB used by all microservices ,  loopback only (127.0.0.1)",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a25",
      "port": "6370",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "Internal Python orchestration/sosrest service",
      "serviceDescription": "Internal Python orchestration/sosrest service ,  loopback only (127.0.0.1)",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a26",
      "port": "7100",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "commonsvcs",
      "serviceDescription": "commonsvcs ,  certificate management, trust store, appliance manager APIs.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a27",
      "port": "7200",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "domainmanager",
      "serviceDescription": "domainmanager ,  domain and cluster lifecycle operations.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a28",
      "port": "7300",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "operationsmanager",
      "serviceDescription": "operationsmanager ,  health, compliance, and operational tasks.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a29",
      "port": "7400",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "lcm",
      "serviceDescription": "lcm ,  upgrade orchestration, bundle management, patch operations.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a2a",
      "port": "7500",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "Node",
      "serviceDescription": "Node.js web UI server ,  serves the SDDC Manager frontend, loopback only.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034e5887ef2531709a2b",
      "port": "7600",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "Python orchestration engine",
      "serviceDescription": "Python orchestration engine ,  FSM task execution (4 worker processes)",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a2c",
      "port": "7900",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "VIP Manager i18n",
      "serviceDescription": "VIP Manager i18n ,  internationalization / presentation layer.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a2d",
      "port": "15051",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "capengine",
      "serviceDescription": "capengine ,  internal capability evaluation gRPC service, loopback only.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a2e",
      "port": "8090",
      "protocol": "TCP",
      "source": "SDDC Manager (internal/loopback)",
      "destination": "SDDC Manager (internal/loopback)",
      "purpose": "cap-workflow-engine",
      "serviceDescription": "cap-workflow-engine ,  capability workflow engine. Present in SDDC Manager 9.0 only; port is exposed by the vip-manager-i18n JVM (pid=1274 shares both 7900 and 8090). Absent from 9.1.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a2f",
      "port": "80",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "Internal nginx reverse proxy ,  loopback only (127.0.0.1 / [",
      "serviceDescription": "Internal nginx reverse proxy ,  loopback only (127.0.0.1 / [::1])",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a30",
      "port": "5432",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "Internal PostgreSQL DB used by all microservices",
      "serviceDescription": "Internal PostgreSQL DB used by all microservices ,  loopback only (127.0.0.1)",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a31",
      "port": "6370",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "VCP Compliance Agent (vapi server)",
      "serviceDescription": "VCP Compliance Agent (vapi server) ,  loopback only. Absent in 9.0, present from 9.1.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a32",
      "port": "7100",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "commonsvcs",
      "serviceDescription": "commonsvcs ,  certificate management, trust store, appliance manager APIs.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a33",
      "port": "7200",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "LCM ,  upgrade orchestration, bundle management (9.1",
      "serviceDescription": "LCM ,  upgrade orchestration, bundle management (9.1: lcm; 9.0: lcm)",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a34",
      "port": "7300",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "domainmanager",
      "serviceDescription": "domainmanager ,  domain and cluster lifecycle operations.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a35",
      "port": "7400",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "operationsmanager",
      "serviceDescription": "operationsmanager ,  health, compliance, and operational tasks.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a36",
      "port": "7500",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "Node",
      "serviceDescription": "Node.js web UI server ,  serves the VCF Installer frontend, loopback only.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a37",
      "port": "7600",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "sosrest Python",
      "serviceDescription": "sosrest Python ,  SOS REST diagnostic / supportability API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03034f5887ef2531709a38",
      "port": "7900",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "VIP Manager i18n",
      "serviceDescription": "VIP Manager i18n ,  internationalization / presentation layer.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303505887ef2531709a39",
      "port": "8090",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "cap-workflow-engine",
      "serviceDescription": "cap-workflow-engine ,  capability workflow engine. Present in 9.0 only; absent from 9.1.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0303505887ef2531709a3a",
      "port": "15051",
      "protocol": "TCP",
      "source": "VCF Installer (internal/loopback)",
      "destination": "VCF Installer (internal/loopback)",
      "purpose": "capengine",
      "serviceDescription": "capengine ,  internal capability evaluation gRPC service, loopback only.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "SDDC Manager",
      "productId": "68591d4d48aeb10d5142cfc8",
      "releases": [
        {
          "id": "6a0303114aec70d0faf92925",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074a4aec70d0faf92926",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Tenant Supervisor Namespace IP Addresses",
      "purpose": "PAIS UI / API / Metrics",
      "serviceDescription": "PAIS data-plane UI, API, and metrics HTTPS access.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074a4aec70d0faf92927",
      "port": "5432",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Tenant-provided Postgres (DSM)",
      "purpose": "PAIS Postgres database",
      "serviceDescription": "PAIS data-plane connection to a tenant-provided Postgres instance (may be a DSM-managed database).",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf92928",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "User Identity Provider (external)",
      "purpose": "Identity Provider (HTTPS)",
      "serviceDescription": "PAIS data plane authenticates users against a customer-configured identity provider.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf92929",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "User Datasources (external)",
      "purpose": "Datasource crawling",
      "serviceDescription": "PAIS crawls user-supplied datasources (S3, Google, SharePoint, and similar) over HTTP/HTTPS.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf9292a",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "User MCP Servers (external)",
      "purpose": "MCP server integration",
      "serviceDescription": "PAIS integrates with customer Model Context Protocol (MCP) servers over HTTP/HTTPS.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf9292b",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "User OTel Collector (external)",
      "purpose": "Observability (OTel)",
      "serviceDescription": "LLM traces sent over the OpenTelemetry protocol to a user-configured observability instance.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf9292c",
      "port": "443",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Nvidia Helm chart server",
      "purpose": "Nvidia Helm charts",
      "serviceDescription": "Downloads Nvidia Helm charts from helm.ngc.nvidia.com/nvidia.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf9292d",
      "port": "443",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Nvidia OCI Registry",
      "purpose": "Nvidia container images",
      "serviceDescription": "Downloads Nvidia container images from nvcr.io.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf9292e",
      "port": "443",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Kubernetes OCI Registry",
      "purpose": "Kubernetes container images",
      "serviceDescription": "Downloads Kubernetes container images from registry.k8s.io.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074b4aec70d0faf9292f",
      "port": "80",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Ubuntu Package Repository",
      "purpose": "Ubuntu packages",
      "serviceDescription": "Downloads Ubuntu packages from archive.ubuntu.com.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92930",
      "port": "443",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Broadcom Artifactory (pais-docker)",
      "purpose": "PAIS model runtime images",
      "serviceDescription": "OCI container images for Model Runtime Engines (vLLM, LlamaCPP, Infinity) served from Broadcom Artifactory at pais-docker.packages.broadcom.com.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92931",
      "port": "443",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "User OCI Registry (external)",
      "purpose": "User-supplied model registry",
      "serviceDescription": "User-configurable OCI registry that hosts model data as OCI artifacts.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92932",
      "port": "53",
      "protocol": "TCP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from the PAIS namespace.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92933",
      "port": "53",
      "protocol": "UDP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from the PAIS namespace.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92934",
      "port": "123",
      "protocol": "UDP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for PAIS workloads.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92935",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the PAIS namespace and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92936",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the PAIS namespace and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074c4aec70d0faf92937",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the PAIS namespace and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03074d4aec70d0faf92938",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "Tenant Supervisor Namespace IP Addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the PAIS namespace and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VMware Private AI Services",
      "productId": "6a0306074e349d6d9c172422",
      "releases": [
        {
          "id": "6a0307115887ef2531709a3b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a3e",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Automation Management IP address",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into the VCF Automation appliance.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a3f",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Automation Management IP address",
      "purpose": "VCF Automation UI / API",
      "serviceDescription": "Primary HTTPS port for the VCF Automation UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a40",
      "port": "587",
      "protocol": "TCP",
      "source": "VCF Automation Management IP address",
      "destination": "Email Server",
      "purpose": "SMTP (alarms)",
      "serviceDescription": "VCF Automation sends emailed notifications via SMTP submission with authentication.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a41",
      "port": "902",
      "protocol": "TCP",
      "source": "VCF Automation Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "VM console access",
      "serviceDescription": "VCF Automation reaches ESX hosts on 902 for VM console operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a42",
      "port": "8008",
      "protocol": "TCP",
      "source": "External Load Balancer",
      "destination": "VCF Automation Management IP address",
      "purpose": "Health check",
      "serviceDescription": "Health status endpoint used by an external load balancer (https://<node>:8008/health).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a43",
      "port": "53",
      "protocol": "TCP",
      "source": "VCF Automation Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Automation.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a44",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Automation Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Automation.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a45",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Automation Management IP address",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for VCF Automation.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a46",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "VCF Automation Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Automation and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a47",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "VCF Automation Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Automation and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c55887ef2531709a48",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "VCF Automation Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Automation and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a49",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "VCF Automation Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Automation and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a4a",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP SSH (admin)",
      "serviceDescription": "Operator/admin SSH into the VCF Management Services Platform nodes underlying this product.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a4b",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a4c",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP UI / API",
      "serviceDescription": "Primary HTTPS port on the VCF Management Services Platform for the UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a4d",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP VAMI",
      "serviceDescription": "VAMI break-glass interface on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a4e",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "vCenter API to VMSP",
      "serviceDescription": "vCenter Server connects to the VCF Management Services Platform over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a4f",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMSP to vCenter / managed products",
      "serviceDescription": "Platform nodes pull VCF component binaries from the Fleet Manager content repository and reach the HTTPS API endpoints of managed products.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a50",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Management API",
      "serviceDescription": "Fleet Manager control plane management API requests to the Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a51",
      "port": "30000",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry on the Platform control plane nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a52",
      "port": "30001",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry (bootstrap)",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry at bootstrap.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a53",
      "port": "30005",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Health Check API",
      "serviceDescription": "Validates the Platform runtime is healthy prior to invoking lifecycle changes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0312c65887ef2531709a54",
      "port": "30006",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Webhook API",
      "serviceDescription": "Webhooks called by Fleet Manager to trigger Day-2 operations on the Platform runtime.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Automation",
      "productId": "68591d1548aeb10d5142cfc7",
      "releases": [
        {
          "id": "68591ea048aeb10d5142cfcd",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141a5887ef2531709a56",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP SSH (admin)",
      "serviceDescription": "Operator/admin SSH into the VCF Management Services Platform nodes underlying this product.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141b5887ef2531709a57",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141b5887ef2531709a58",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP UI / API",
      "serviceDescription": "Primary HTTPS port on the VCF Management Services Platform for the UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141b5887ef2531709a59",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP VAMI",
      "serviceDescription": "VAMI break-glass interface on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141c5887ef2531709a5a",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "vCenter API to VMSP",
      "serviceDescription": "vCenter Server connects to the VCF Management Services Platform over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141c5887ef2531709a5b",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMSP to vCenter / managed products",
      "serviceDescription": "Platform nodes pull VCF component binaries from the Fleet Manager content repository and reach the HTTPS API endpoints of managed products.",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141c5887ef2531709a5c",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Management API",
      "serviceDescription": "Fleet Manager control plane management API requests to the Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141d5887ef2531709a5d",
      "port": "30000",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry on the Platform control plane nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141d5887ef2531709a5e",
      "port": "30001",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry (bootstrap)",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry at bootstrap.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141e5887ef2531709a5f",
      "port": "30005",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Health Check API",
      "serviceDescription": "Validates the Platform runtime is healthy prior to invoking lifecycle changes.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141e5887ef2531709a60",
      "port": "30006",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Webhook API",
      "serviceDescription": "Webhooks called by Fleet Manager to trigger Day-2 operations on the Platform runtime.",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141e5887ef2531709a61",
      "port": "53",
      "protocol": "TCP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Management Services Platform IP addresses.",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141f5887ef2531709a62",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Management Services Platform IP addresses.",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141f5887ef2531709a63",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for VCF Management Services Platform IP addresses.",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03141f5887ef2531709a64",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Management Services Platform IP addresses and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0314205887ef2531709a65",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Management Services Platform IP addresses and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0314205887ef2531709a66",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Management Services Platform IP addresses and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0314215887ef2531709a67",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Management Services Platform IP addresses and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0b1470c2b516e599a35d62",
      "port": "5480",
      "protocol": "TCP",
      "source": "SDDC Manager IP address",
      "destination": "VCF Management Services Platform IP address",
      "purpose": "VCF Management Services Mangement Interface",
      "serviceDescription": "VCF Installer to VCF Management Services",
      "classification": "Inbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0b91f09044725e5fb7c2ac",
      "port": "443",
      "protocol": "TCP",
      "source": "Software Depot",
      "destination": "Broadcom Public URLs",
      "purpose": "Broadcom public URL access",
      "serviceDescription": "HTTPS to Broadcom-hosted public URLs for software depot (binaries, compatibility data, etc)",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0b91f19044725e5fb7c2ad",
      "port": "443",
      "protocol": "TCP",
      "source": "Software Depot",
      "destination": "Offline Depot ",
      "purpose": "Access to customer-supplied offline depot ",
      "serviceDescription": "Obtain binaries, compatibility data, etc. from customer-supplied offline depot",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0b91f19044725e5fb7c2ae",
      "port": "80",
      "protocol": "TCP",
      "source": "Software Depot",
      "destination": "Offline Depot ",
      "purpose": "Access to customer-supplied offline depot ",
      "serviceDescription": "Obtain binaries, compatibility data, etc. from customer-supplied offline depot",
      "classification": "Outbound",
      "publishDate": "2026-05-16T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a10a0f39044725e5fb7c2f9",
      "port": "5480",
      "protocol": "TCP",
      "source": "VCF Installer",
      "destination": "VCF Management Services Platform IP Address",
      "purpose": "VCF Management Services Interface",
      "serviceDescription": "VCF Installer to VCF Management Services",
      "classification": "Outbound",
      "publishDate": "2026-05-19T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a548eb428e5d2932fc84aed",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Salt RaaS",
      "destination": "VCF Management Services Platform IP Address",
      "purpose": "VCF Salt RaaS (admin)",
      "serviceDescription": "Port used between VCF Salt RaaS and Salt Master for internal communications",
      "classification": "Both",
      "publishDate": "2026-09-06T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        },
        {
          "id": "6aa1286a4a973bfa11ce1650",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a548eb428e5d2932fc84aee",
      "port": "4506",
      "protocol": "TCP",
      "source": "VCF Salt Master",
      "destination": "VCF Management Services Platform IP Address",
      "purpose": "VCF Salt Master Request Server",
      "serviceDescription": "Port used for endpoints to return job data",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        },
        {
          "id": "6aa1286a4a973bfa11ce1650",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a548eb428e5d2932fc84aef",
      "port": "4505",
      "protocol": "TCP",
      "source": "VCF Salt Master",
      "destination": "VCF Management Services Platform IP Address",
      "purpose": "VCF Salt Master Publisher",
      "serviceDescription": "Ports used by Salt Master to publish jobs to endpoints",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6a0313d25887ef2531709a55",
          "name": "9.1.0"
        },
        {
          "id": "6aa1286a4a973bfa11ce1650",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6aa129390f89d2eff4a10105",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Salt RaaS",
      "destination": "VCF Management Services Platform IP Address",
      "purpose": "VMware Salt for VCF Components API",
      "serviceDescription": "API Port used to accept VMware Salt for VCF Component API Calls",
      "classification": "Inbound",
      "publishDate": "2026-09-06T00:00:00Z",
      "product": "VCF Management Services",
      "productId": "6a0313621809eae1a581f68f",
      "releases": [
        {
          "id": "6aa1286a4a973bfa11ce1650",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a031f4b4aec70d0faf9293c",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "VCF Ops for Logs UI",
      "serviceDescription": "Primary HTTPS port for the VCF Operations for Logs UI.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4b4aec70d0faf9293d",
      "port": "9543",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "VCF Ops for Logs API",
      "serviceDescription": "REST API for VCF Operations for Logs.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4b4aec70d0faf9293e",
      "port": "9000",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Log ingestion (CFAPI)",
      "serviceDescription": "VCF Operations for Logs ingestion API over plain HTTP.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4b4aec70d0faf9293f",
      "port": "9543",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Log ingestion (CFAPI/TLS)",
      "serviceDescription": "VCF Operations for Logs ingestion API over TLS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4c4aec70d0faf92940",
      "port": "514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog",
      "serviceDescription": "Syslog ingestion (plaintext).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4c4aec70d0faf92941",
      "port": "514",
      "protocol": "UDP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog",
      "serviceDescription": "Syslog ingestion (plaintext).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4c4aec70d0faf92942",
      "port": "1514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog over TLS",
      "serviceDescription": "Syslog ingestion over TLS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4c4aec70d0faf92943",
      "port": "6514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Syslog over TLS",
      "serviceDescription": "Syslog ingestion over TLS (alternate port).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4c4aec70d0faf92945",
      "port": "9543",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "CPLF log ingestion (CFAPI/TLS)",
      "serviceDescription": "VCF Operations for Logs CPLF ingestion API over TLS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4c4aec70d0faf92946",
      "port": "514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "CPLF Syslog",
      "serviceDescription": "Syslog ingestion to the CPLF (plaintext).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf92947",
      "port": "514",
      "protocol": "UDP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "CPLF Syslog",
      "serviceDescription": "Syslog ingestion to the CPLF (plaintext).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf92948",
      "port": "1514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "CPLF Syslog over TLS",
      "serviceDescription": "Syslog ingestion to the CPLF over TLS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf92949",
      "port": "6514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "CPLF Syslog over TLS",
      "serviceDescription": "Syslog ingestion to the CPLF over TLS (alternate port).",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf9294a",
      "port": "8080",
      "protocol": "TCP",
      "source": "Supervisor (VKS) Management IP address",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "VKS health probe",
      "serviceDescription": "Supervisor / Kubernetes health-probe traffic to VCF Operations for Logs.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf9294b",
      "port": "7000",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "Cassandra replication",
      "serviceDescription": "Cassandra replication and query between VCF Operations for Logs cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf9294c",
      "port": "7001",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "Cassandra SSL replication",
      "serviceDescription": "Cassandra replication and query over SSL between cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4d4aec70d0faf9294d",
      "port": "9042",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "Cassandra native protocol",
      "serviceDescription": "Cassandra native-protocol client connections between cluster components.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf9294e",
      "port": "9200",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "OpenSearch indexing",
      "serviceDescription": "OpenSearch indexing and query traffic between cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf9294f",
      "port": "9300",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "OpenSearch clustering",
      "serviceDescription": "OpenSearch clustering traffic between cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92950",
      "port": "59778",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "Thrift",
      "serviceDescription": "Thrift control traffic between cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92951",
      "port": "16520-16580",
      "protocol": "TCP",
      "source": "VCF Operations for Logs cluster (internal)",
      "destination": "VCF Operations for Logs cluster (internal)",
      "purpose": "Thrift data range",
      "serviceDescription": "Thrift data port range between cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92952",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter integration",
      "serviceDescription": "REST API integration with vCenter Server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92953",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "Supervisor integration",
      "serviceDescription": "REST API integration with the WCP/vSphere Supervisor.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92954",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "NSX Manager",
      "purpose": "NSX integration",
      "serviceDescription": "REST API integration with NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92955",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "VCF Operations HCX Management IP address",
      "purpose": "HCX integration",
      "serviceDescription": "REST API integration with VCF Operations HCX.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92956",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "VCF Operations Management IP address",
      "purpose": "VCF Operations integration",
      "serviceDescription": "REST API integration with VCF Operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92957",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "VCF Operations for Networks Management IP address",
      "purpose": "VCF Operations for Networks integration",
      "serviceDescription": "REST API integration with VCF Operations for Networks.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4e4aec70d0faf92958",
      "port": "636",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "LDAPS authentication to Active Directory.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf92959",
      "port": "53",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf9295a",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf9295b",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf9295e",
      "port": "1514",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Syslog Servers",
      "purpose": "Syslog over TLS forward",
      "serviceDescription": "Forwarding syslog over TLS to downstream destinations.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf9295f",
      "port": "8443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "S3-compatible Storage",
      "purpose": "S3 archive",
      "serviceDescription": "S3-compatible storage (SeaweedFS) for log archive.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf92960",
      "port": "2049",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "NFS Storage Server",
      "purpose": "NFS storage",
      "serviceDescription": "NFS-mounted storage for archive. Uses standard NFSv3 portmapper / mountd / lockd / statd ports on the storage server.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf92961",
      "port": "9543",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Legacy Log Insight cluster",
      "purpose": "Migration from Legacy LI",
      "serviceDescription": "REST API access to a legacy Log Insight cluster during migration.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f4f4aec70d0faf92962",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Broadcom Telemetry Service",
      "purpose": "Telemetry",
      "serviceDescription": "Broadcom phone-home telemetry.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92963",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Logs and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92964",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Logs and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92965",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Logs and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92966",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Logs and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92967",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP SSH (admin)",
      "serviceDescription": "Operator/admin SSH into the VCF Management Services Platform nodes underlying this product.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92968",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf92969",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP UI / API",
      "serviceDescription": "Primary HTTPS port on the VCF Management Services Platform for the UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf9296a",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP VAMI",
      "serviceDescription": "VAMI break-glass interface on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf9296b",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "vCenter API to VMSP",
      "serviceDescription": "vCenter Server connects to the VCF Management Services Platform over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf9296c",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMSP to vCenter / managed products",
      "serviceDescription": "Platform nodes pull VCF component binaries from the Fleet Manager content repository and reach the HTTPS API endpoints of managed products.",
      "classification": "Outbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f504aec70d0faf9296d",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Management API",
      "serviceDescription": "Fleet Manager control plane management API requests to the Platform.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f514aec70d0faf9296e",
      "port": "30000",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry on the Platform control plane nodes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f514aec70d0faf9296f",
      "port": "30001",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry (bootstrap)",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry at bootstrap.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f514aec70d0faf92970",
      "port": "30005",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Health Check API",
      "serviceDescription": "Validates the Platform runtime is healthy prior to invoking lifecycle changes.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a031f514aec70d0faf92971",
      "port": "30006",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Webhook API",
      "serviceDescription": "Webhooks called by Fleet Manager to trigger Day-2 operations on the Platform runtime.",
      "classification": "Inbound",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a031ef64aec70d0faf9293b",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15a5",
      "port": "9543",
      "protocol": "HTTPS",
      "source": "Log Source",
      "destination": "VCF Operations for Logs",
      "purpose": "VCF Operations for Logs Ingestion API over TLS",
      "serviceDescription": "VCF Ops Logs Agents sending log data to VCF Ops Logs.",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15a6",
      "port": "1514",
      "protocol": "TCP",
      "source": "Log Source",
      "destination": "VCF Operations for Logs",
      "purpose": "Syslog over TLS",
      "serviceDescription": "ESXi hosts sending log data to VCF Ops Logs.",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15a7",
      "port": "9543",
      "protocol": "HTTPS",
      "source": "API Clients",
      "destination": "VCF Operations for Logs",
      "purpose": "VCF Operations for Logs API",
      "serviceDescription": "Clients interacting with the VCF Operations for Logs API surface",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15a8",
      "port": "443",
      "protocol": "HTTPS",
      "source": "UI Clients",
      "destination": "VCF Operations for Logs",
      "purpose": "VCF Operations for Logs Local UI",
      "serviceDescription": "Users interacting with the VCF Operations for Logs Local UI",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15a9",
      "port": "9200",
      "protocol": "TCP",
      "source": "VCF Operations for Logs",
      "destination": "VCF Operations for Logs",
      "purpose": "OpenSearch indexing and query",
      "serviceDescription": "OpenSearch port for client communication, indexing, and search queries.",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15aa",
      "port": "9300",
      "protocol": "TCP",
      "source": "VCF Operations for Logs",
      "destination": "VCF Operations for Logs",
      "purpose": "OpenSearchclustering",
      "serviceDescription": "OpenSearch port for internode cluster communication.",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15ab",
      "port": "8080",
      "protocol": "HTTP",
      "source": "VMSP/Kubernetes",
      "destination": "VCF Operations for Logs",
      "purpose": "VCF Operations for Logs Health",
      "serviceDescription": "Health/Readiness probe by Kubernetes",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15ac",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs (and CPLF)",
      "destination": "vCenter Server",
      "purpose": "vCenter Server",
      "serviceDescription": "Configure log collection, collect vCenter events, inventory sync (hosts, VMs)",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15ad",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs (and CPLF)",
      "destination": "WCP/vSphere Supervisor",
      "purpose": "WCP/vSphere Supervisor",
      "serviceDescription": "Configure log collection on Supervisor clusters",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15ae",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs (and CPLF)",
      "destination": "NSX Manager",
      "purpose": "NSX Manager",
      "serviceDescription": "Configure log collection on NSX",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15af",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs (and CPLF)",
      "destination": "HCX",
      "purpose": "HCX",
      "serviceDescription": "Configure log collection on HCX",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b0",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs",
      "destination": "vROps",
      "purpose": "vROps",
      "serviceDescription": "Token auth, license sync, alert forwarding, cert renewal, log collection configuration",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b1",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs",
      "destination": "vRNI",
      "purpose": "vRNI",
      "serviceDescription": "Configure log collection on NI platform, collectors",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b2",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs",
      "destination": "VMSP Platform",
      "purpose": "VMSP Platform",
      "serviceDescription": "Configure log collection for VIDB and LI components (delegated to VMSP)",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b4",
      "port": "1514",
      "protocol": "TLS",
      "source": "VCF Operations for Logs",
      "destination": "Syslog destinations",
      "purpose": "Syslog destinations",
      "serviceDescription": "Forward logs to external syslog servers over TLS",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b5",
      "port": "8443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs",
      "destination": "S3-compatible storage (SeaweedFS)",
      "purpose": "S3-compatible storage (SeaweedFS)",
      "serviceDescription": "Backup/restore, archive to seaweedfs-s3.vmsp-platform.svc.cluster.local:8443",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b6",
      "port": "Standard NFS ports",
      "protocol": "NFS",
      "source": "VCF Operations for Logs",
      "destination": "NFS storage",
      "purpose": "NFS storage",
      "serviceDescription": "External log archive storage",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b7",
      "port": "9543",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs",
      "destination": "Legacy Log Insight cluster",
      "purpose": "Legacy Log Insight cluster",
      "serviceDescription": "Migration: pull config/data from legacy vRealize Log Insight during upgrade",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f214a973bfa11ce15b8",
      "port": "443",
      "protocol": "HTTPS",
      "source": "VCF Operations for Logs",
      "destination": "Broadcom Phone Home (telemetry)",
      "purpose": "Broadcom Phone Home (telemetry)",
      "serviceDescription": "CEIP telemetry upload to Broadcom (VSP_PRODUCTION environment)",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f224a973bfa11ce15b9",
      "port": "9543",
      "protocol": "HTTPS",
      "source": "Log Source",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "VCF Operations for Logs CPLF Ingestion API over TLS",
      "serviceDescription": "VCF Ops Logs Agents sending log data to VCF Ops Logs CPLF.",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a993f224a973bfa11ce15ba",
      "port": "1514",
      "protocol": "TCP",
      "source": "Log Source",
      "destination": "VCF Operations for Logs CPLF",
      "purpose": "Syslog over TLS",
      "serviceDescription": "ESXi hosts sending log data to VCF Ops Logs CPLF.",
      "classification": "N/A",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "Log Management",
      "productId": "6859219a48aeb10d5142cfd0",
      "releases": [
        {
          "id": "6a993db00f89d2eff4a10104",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0e9d73c2b516e599a35dc8",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "License Server Management IP address",
      "purpose": "License management (HTTPS)",
      "serviceDescription": "License synchronization with vCenter",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dcd",
      "port": "53",
      "protocol": "UDP",
      "source": "License Server Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from License Server.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dce",
      "port": "53",
      "protocol": "TCP",
      "source": "License Server Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from License Server.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dcf",
      "port": "443",
      "protocol": "TCP",
      "source": "License Server Management IP address",
      "destination": "VCF Operations Management IP address",
      "purpose": "License status updates (HTTPS)",
      "serviceDescription": "License Server sends status updates to VCF Operations.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd0",
      "port": "30006",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Webhook API",
      "serviceDescription": "Webhooks called by Fleet Manager to trigger Day-2 operations on the Platform runtime.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd1",
      "port": "30005",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Health Check API",
      "serviceDescription": "Validates the Platform runtime is healthy prior to invoking lifecycle changes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd2",
      "port": "30001",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry (bootstrap)",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry at bootstrap.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd3",
      "port": "30000",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry on the Platform control plane nodes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd4",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Management API",
      "serviceDescription": "Fleet Manager control plane management API requests to the Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd5",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMSP to vCenter / managed products",
      "serviceDescription": "Platform nodes pull VCF component binaries from the Fleet Manager content repository and reach the HTTPS API endpoints of managed products.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d74c2b516e599a35dd6",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "vCenter API to VMSP",
      "serviceDescription": "vCenter Server connects to the VCF Management Services Platform over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35de8",
      "port": "30006",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Webhook API",
      "serviceDescription": "Webhooks called by Fleet Manager to trigger Day-2 operations on the Platform runtime.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35de9",
      "port": "30005",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Health Check API",
      "serviceDescription": "Validates the Platform runtime is healthy prior to invoking lifecycle changes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35dea",
      "port": "30001",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry (bootstrap)",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry at bootstrap.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35deb",
      "port": "30000",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry on the Platform control plane nodes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35dec",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Management API",
      "serviceDescription": "Fleet Manager control plane management API requests to the Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35ded",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Management Services Platform IP addresses",
      "destination": "vCenter Server Management IP address",
      "purpose": "VMSP to vCenter / managed products",
      "serviceDescription": "Platform nodes pull VCF component binaries from the Fleet Manager content repository and reach the HTTPS API endpoints of managed products.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35dee",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "vCenter API to VMSP",
      "serviceDescription": "vCenter Server connects to the VCF Management Services Platform over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d76c2b516e599a35def",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP VAMI",
      "serviceDescription": "VAMI break-glass interface on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df0",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP UI / API",
      "serviceDescription": "Primary HTTPS port on the VCF Management Services Platform for the UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df1",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df2",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP SSH (admin)",
      "serviceDescription": "Operator/admin SSH into the VCF Management Services Platform nodes underlying this product.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df3",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations cluster nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df4",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations cluster nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df5",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations cluster nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df6",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations cluster nodes and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df7",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "Log Assist Cloud Service",
      "purpose": "Log Assist to cloud service",
      "serviceDescription": "Log Assist Worker to the Log Assist Cloud Service hosted by Broadcom GTO.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df8",
      "port": "5480",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "Log Assist to VMSP VAMI",
      "serviceDescription": "Log Assist Worker to the Supervisor VAMI.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35df9",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "Log Assist to VMSP",
      "serviceDescription": "Log Assist Worker to the Supervisor (VMSP) identity service and VCF MS Runtime.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35dfa",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "SDDC Manager Management IP address",
      "purpose": "Log Assist to SDDC Manager",
      "serviceDescription": "Log Assist Worker to SDDC Manager (SOS / support-bundles).",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35dfb",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "VCF Operations Management IP address",
      "purpose": "Log Assist to VCF Ops",
      "serviceDescription": "Log Assist Worker to VCF Operations (vmware-casa).",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d77c2b516e599a35dfc",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "NSX Manager",
      "purpose": "Log Assist to NSX",
      "serviceDescription": "Log Assist Worker to NSX Manager for administration and node services.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35dfd",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "vCenter Server Management IP address",
      "purpose": "Log Assist to vCenter",
      "serviceDescription": "Log Assist Worker to vCenter VMODL API and namespace management.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35dfe",
      "port": "443",
      "protocol": "TCP",
      "source": "Log Assist Worker (Unified Cloud Proxy)",
      "destination": "ESX Management IP addresses",
      "purpose": "Log Assist to ESX",
      "serviceDescription": "Log Assist Worker to ESX hosts (cgi-bin/vm-support.cgi) for support bundle collection.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35dff",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from cluster nodes and Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e00",
      "port": "53",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from cluster nodes and Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e01",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization from cluster nodes and Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e02",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "SNMP Management System",
      "purpose": "SNMP",
      "serviceDescription": "SNMP from cluster nodes and Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e03",
      "port": "25",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Email Server",
      "purpose": "SMTP",
      "serviceDescription": "SMTP for notifications from cluster nodes and Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e04",
      "port": "3269",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS Global Catalog",
      "serviceDescription": "LDAPS Global Catalog queries to Active Directory.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e05",
      "port": "3268",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP Global Catalog",
      "serviceDescription": "LDAP Global Catalog queries to Active Directory.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e06",
      "port": "636",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS",
      "serviceDescription": "LDAPS authentication to Active Directory.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e07",
      "port": "389",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP",
      "serviceDescription": "LDAP authentication to Active Directory.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e08",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter integration",
      "serviceDescription": "VCF Operations to vCenter Server. Same destination covers any Platform Services Controller endpoints.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d78c2b516e599a35e09",
      "port": "6514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Syslog over TLS",
      "serviceDescription": "Syslog over TLS ingestion at Cloud Proxies.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e0a",
      "port": "1514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Syslog over TLS",
      "serviceDescription": "Syslog over TLS ingestion at Cloud Proxies.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e0b",
      "port": "514",
      "protocol": "UDP",
      "source": "Log Sources",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Syslog",
      "serviceDescription": "Syslog ingestion at Cloud Proxies.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e0c",
      "port": "514",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Syslog",
      "serviceDescription": "Syslog ingestion at Cloud Proxies.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e0d",
      "port": "9543",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Log ingestion (CFAPI/TLS)",
      "serviceDescription": "Log ingestion at Cloud Proxies over TLS.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e0e",
      "port": "9000",
      "protocol": "TCP",
      "source": "Log Sources",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Log ingestion (CFAPI)",
      "serviceDescription": "Log ingestion at Cloud Proxies (plain HTTP).",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e0f",
      "port": "4505-4506",
      "protocol": "TCP",
      "source": "VCF Operations Endpoint VM",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Salt Control Plane",
      "serviceDescription": "Salt Control Plane traffic from endpoint VMs to Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e10",
      "port": "8443",
      "protocol": "TCP",
      "source": "VCF Operations Endpoint VM",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "User-managed Telegraf",
      "serviceDescription": "User-managed and open-source Telegraf traffic from endpoint VMs to Cloud Proxies.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e11",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Endpoint VM",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Endpoint VM to Cloud Proxy",
      "serviceDescription": "Endpoint VMs (physical or virtual) to Cloud Proxy over HTTPS.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e12",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Cloud Proxy",
      "destination": "VCF Operations Cluster Nodes",
      "purpose": "Cloud Proxy to cluster",
      "serviceDescription": "Cloud Proxy traffic to Primary, Replica, and Data nodes.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e13",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Cloud Proxy",
      "destination": "ESX Management IP addresses",
      "purpose": "Cloud Proxy to ESX",
      "serviceDescription": "Cloud Proxy to ESX hosts hosting endpoint VMs.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e14",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Telegraf (Cloud Proxy)",
      "serviceDescription": "Open-source Telegraf traffic between Cloud Proxies.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d79c2b516e599a35e15",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "NTP (cluster)",
      "serviceDescription": "NTP between Data/Witness nodes/Cloud Proxies and Primary/Replica nodes.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e16",
      "port": "20002-20010",
      "protocol": "UDP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Gemfire",
      "serviceDescription": "Gemfire cluster traffic between Data and Primary/Replica nodes.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e17",
      "port": "20002-20010",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Gemfire",
      "serviceDescription": "Gemfire cluster traffic between Data and Primary/Replica nodes.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e18",
      "port": "10002-10010",
      "protocol": "UDP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Gemfire",
      "serviceDescription": "Gemfire cluster traffic.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e19",
      "port": "10002-10010",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Gemfire",
      "serviceDescription": "Gemfire cluster traffic.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e1a",
      "port": "10000",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Gemfire",
      "serviceDescription": "Gemfire cluster traffic.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e1b",
      "port": "6061",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Gemfire",
      "serviceDescription": "Gemfire cluster traffic.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e1c",
      "port": "5433",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Postgres Central DB",
      "serviceDescription": "Communication with the Postgres Central DB on the Primary node from Data nodes.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e1d",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Cluster (internal)",
      "destination": "VCF Operations Cluster (internal)",
      "purpose": "Cluster HTTPS",
      "serviceDescription": "Intra-cluster HTTPS between Primary, Replica, Data, and Witness nodes.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e1e",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Cluster Nodes",
      "destination": "Broadcom Business Services",
      "purpose": "Business Services console",
      "serviceDescription": "Outbound communication from the Primary node to the VCF Business Services console at eapi.broadcom.com and VCF.broadcom.com.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ac2b516e599a35e1f",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations Cluster Nodes",
      "purpose": "VCF Operations UI / API",
      "serviceDescription": "Primary HTTPS port for the VCF Operations UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e20",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations Cluster Nodes",
      "purpose": "HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS for the VCF Operations UI.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e21",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations Cluster Nodes",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into VCF Operations cluster nodes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e22",
      "port": "443",
      "protocol": "TCP",
      "source": "Cloud Proxy",
      "destination": "VMSP Cluster",
      "purpose": "Management, Policy Sync, and Data Querying",
      "serviceDescription": "VMSP Envoy Proxy",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e23",
      "port": "443",
      "protocol": "TCP",
      "source": "User Workstation",
      "destination": "VMSP Cluster",
      "purpose": "Accessing Troubleshooting Workbench UI",
      "serviceDescription": "Data Query Service (DQS)",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e24",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Edge / Host",
      "destination": "VMSP Cluster",
      "purpose": "gRPC Telemetry Stream for network data",
      "serviceDescription": "NetOps Collector Service",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e25",
      "port": "443",
      "protocol": "TCP",
      "source": "VMSP Cluster",
      "destination": "VCSA / ESXi",
      "purpose": "vAPI Streaming and vmodl1 Performance Pull",
      "serviceDescription": "vStats / StatsRegistry",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e26",
      "port": "443",
      "protocol": "TCP",
      "source": "Cloud Proxy",
      "destination": "NSX Manager",
      "purpose": "Configuration and Subscription management",
      "serviceDescription": "NSX API",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7bc2b516e599a35e27",
      "port": "443",
      "protocol": "TCP",
      "source": "VMSP Cluster",
      "destination": "Cloud Proxy",
      "purpose": "Periodic push of VC & Policy details",
      "serviceDescription": "Real-Time Metrics Adapter",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e28",
      "port": "8443",
      "protocol": "TCP",
      "source": "VMSP Services",
      "destination": "VMSP Services",
      "purpose": "Intra-cluster communication for job distribution",
      "serviceDescription": "CCS / Collector SDKs",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e29",
      "port": "8443",
      "protocol": "TCP",
      "source": "VMSP Services",
      "destination": "ClickHouse",
      "purpose": "Internal data writes to ClickHouse repository",
      "serviceDescription": "Database Ingestion",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e2a",
      "port": "9000",
      "protocol": "TCP",
      "source": "VMSP Services",
      "destination": "ClickHouse",
      "purpose": "High-performance internal database queries/ingest",
      "serviceDescription": "ClickHouse Native Protocol",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e2b",
      "port": "13180",
      "protocol": "TCP",
      "source": "VCSA (Internal)",
      "destination": "VCSA (Internal)",
      "purpose": "Internal VCSA telemetry aggregation for Envoy",
      "serviceDescription": "vStats to VPXD",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e2c",
      "port": "80",
      "protocol": "TCP",
      "source": "VCSA (Internal)",
      "destination": "VCSA (Internal)",
      "purpose": "Internal legacy VMOMI pulls within VCenter",
      "serviceDescription": "vStats to vSAN/VPXD",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e2d",
      "port": "443",
      "protocol": "TCP",
      "source": "Cloud Proxy",
      "destination": "VMSP Cluster",
      "purpose": "Management, Policy Sync, and Data Querying",
      "serviceDescription": "VMSP Envoy Proxy",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7cc2b516e599a35e2e",
      "port": "443",
      "protocol": "TCP",
      "source": "User Workstation",
      "destination": "VMSP Cluster",
      "purpose": "Accessing Troubleshooting Workbench UI",
      "serviceDescription": "Data Query Service (DQS)",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e2f",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Edge / Host",
      "destination": "VMSP Cluster",
      "purpose": "gRPC Telemetry Stream for network data",
      "serviceDescription": "NetOps Collector Service",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e30",
      "port": "443",
      "protocol": "TCP",
      "source": "VMSP Cluster",
      "destination": "VCSA / ESXi",
      "purpose": "vAPI Streaming and vmodl1 Performance Pull",
      "serviceDescription": "vStats / StatsRegistry",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e31",
      "port": "443",
      "protocol": "TCP",
      "source": "Cloud Proxy",
      "destination": "NSX Manager",
      "purpose": "Configuration and Subscription management",
      "serviceDescription": "NSX API",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e32",
      "port": "443",
      "protocol": "TCP",
      "source": "VMSP Cluster",
      "destination": "Cloud Proxy",
      "purpose": "Periodic push of VC & Policy details",
      "serviceDescription": "Real-Time Metrics Adapter",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e33",
      "port": "8443",
      "protocol": "TCP",
      "source": "VMSP Services",
      "destination": "VMSP Services",
      "purpose": "Intra-cluster communication for job distribution",
      "serviceDescription": "CCS / Collector SDKs",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e34",
      "port": "8443",
      "protocol": "TCP",
      "source": "VMSP Services",
      "destination": "ClickHouse",
      "purpose": "Internal data writes to ClickHouse repository",
      "serviceDescription": "Database Ingestion",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e35",
      "port": "9000",
      "protocol": "TCP",
      "source": "VMSP Services",
      "destination": "ClickHouse",
      "purpose": "High-performance internal database queries/ingest",
      "serviceDescription": "ClickHouse Native Protocol",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7dc2b516e599a35e36",
      "port": "13180",
      "protocol": "TCP",
      "source": "VCSA (Internal)",
      "destination": "VCSA (Internal)",
      "purpose": "Internal VCSA telemetry aggregation for Envoy",
      "serviceDescription": "vStats to VPXD",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a0e9d7ec2b516e599a35e37",
      "port": "80",
      "protocol": "TCP",
      "source": "VCSA (Internal)",
      "destination": "VCSA (Internal)",
      "purpose": "Internal legacy VMOMI pulls within VCenter",
      "serviceDescription": "vStats to vSAN/VPXD",
      "classification": "Internal",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "VCF Operations",
      "productId": "68591cf948aeb10d5142cfc6",
      "releases": [
        {
          "id": "6a0321445887ef2531709a6a",
          "name": "VCF Operations 9.1.0.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92973",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "Broadcom Telemetry Service",
      "purpose": "Telemetry",
      "serviceDescription": "Collect usage data of HCX operations.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92974",
      "port": "5201",
      "protocol": "UDP",
      "source": "HCX-IX-I (Initiator at the Source)",
      "destination": "HCX-IX-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92975",
      "port": "5201",
      "protocol": "TCP",
      "source": "HCX-NE-I (Initiator at the Source)",
      "destination": "HCX-NE-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92976",
      "port": "5201",
      "protocol": "UDP",
      "source": "HCX-NE-I (Initiator at the Source)",
      "destination": "HCX-NE-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92977",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "HCX Manager",
      "purpose": "SSH",
      "serviceDescription": "Secure shell connection is used to launch the HCX Central CLI.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92978",
      "port": "4500",
      "protocol": "UDP",
      "source": "Interconnect (HCX-IX at Source)",
      "destination": "Interconnect (HCX-IX at Destination)",
      "purpose": "HCX WAN Transport Suite B Cryptography; IKEv2",
      "serviceDescription": "The IX transport path carries HCX migration and DR traffic.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf92979",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Service Mesh Deployment. HCX Bulk Migration Control",
      "serviceDescription": "OVF Import / Service Appliance Deployment. HCX Bulk Migration Control Connections.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf9297a",
      "port": "5201",
      "protocol": "TCP",
      "source": "HCX-IX-I (Initiator at the Source)",
      "destination": "HCX-IX-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233d4aec70d0faf9297b",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "HCX Multi-Site Management",
      "serviceDescription": "Site Pairing and ongoing authentication and management of HCX service jobs coordinated across the paired environments.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf9297c",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "vCenter Server Management IP address",
      "purpose": "HCX Integration with vSphere",
      "serviceDescription": "vSphere API, vSphere 6.0+ SSO Lookup Service.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf9297d",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "NSX Manager",
      "purpose": "HCX Integration with NSX",
      "serviceDescription": "NSX API. Optional at the Source (if NSX networks will not be extended). Required at the Destination (SDDC).",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf9297e",
      "port": "53",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "DNS Resolvers",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Name Resolution.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf9297f",
      "port": "53",
      "protocol": "UDP",
      "source": "HCX Manager",
      "destination": "DNS Resolvers",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Name Resolution.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92980",
      "port": "514",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "Syslog Servers",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Syslog Originator to Syslog Collector.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92981",
      "port": "514",
      "protocol": "UDP",
      "source": "HCX Manager",
      "destination": "Syslog Servers",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Syslog Originator to Syslog Collector.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92982",
      "port": "9443",
      "protocol": "TCP",
      "source": "HCX Manager (Connector/Source)",
      "destination": "Sentinel Gateway (HCX-SGW)",
      "purpose": "OSAM Service Management",
      "serviceDescription": "HCX Service Appliance Configuration and Control.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92983",
      "port": "902",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX)",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Bulk Migration",
      "serviceDescription": "HCX Bulk Migration data path.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92984",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "HCX-IX-I (Initiator at the Source)",
      "destination": "HCX-IX-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92985",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "HCX-IX-I (Initiator at the Source)",
      "destination": "HCX-IX-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92986",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "HCX-IX-I (Initiator at the Source)",
      "destination": "HCX-IX-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233e4aec70d0faf92987",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "HCX-IX-I (Initiator at the Source)",
      "destination": "HCX-IX-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-05-09T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf92988",
      "port": "44500 to 44502",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX at Destination)",
      "destination": "Sentinel Data Receiver (HCX-SDR at Destination)",
      "purpose": "OSAM Data Transfer",
      "serviceDescription": "Virtual Machine Data Transfer.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf92989",
      "port": "44500 to 44600",
      "protocol": "TCP",
      "source": "Sentinel Gateway (HCX-SGW at Source)",
      "destination": "Interconnect (HCX-IX at Source)",
      "purpose": "OSAM Data Transfer",
      "serviceDescription": "Virtual Machine Data Transfer.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf9298a",
      "port": "902",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Migration Services",
      "serviceDescription": "HCX Assisted vMotion for NSX V2T.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf9298b",
      "port": "9555",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX)",
      "destination": "HCX Manager",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "Service Mesh Diagnostics for Management.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf9298c",
      "port": "9555",
      "protocol": "TCP",
      "source": "Network Extension (HCX-NE)",
      "destination": "HCX Manager",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "Service Mesh Diagnostics for Management.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf9298d",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "HCX-NE-I (Initiator at the Source)",
      "destination": "HCX-NE-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf9298e",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "HCX-NE-I (Initiator at the Source)",
      "destination": "HCX-NE-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf9298f",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "HCX-NE-I (Initiator at the Source)",
      "destination": "HCX-NE-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf92990",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "HCX-NE-I (Initiator at the Source)",
      "destination": "HCX-NE-R (Receiver at the Destination)",
      "purpose": "HCX Diagnostics",
      "serviceDescription": "CCLI Perftest for Site to Site Connectivity and Performance Diagnostics.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf92991",
      "port": "123",
      "protocol": "UDP",
      "source": "HCX Manager",
      "destination": "NTP Server",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Time Synchronization.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a03233f4aec70d0faf92992",
      "port": "4500-4628",
      "protocol": "UDP",
      "source": "Source IX/NE UDP Port Range 4500-4628",
      "destination": "Destination IX/NE UDP Port 4500",
      "purpose": "Application Path Resiliency (APR)",
      "serviceDescription": "APR creates 8 tunnels per HCX Uplink for transport path resiliency.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92993",
      "port": "4500",
      "protocol": "UDP",
      "source": "Network Extension (HCX-NE at Source)",
      "destination": "Network Extension (HCX-NE at Destination)",
      "purpose": "HCX WAN Transport Suite B Cryptography; IKEv2",
      "serviceDescription": "The NE transport path is used when virtual machines in the source network communicate with virtual machines in the HCX Extended network.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92994",
      "port": "3784",
      "protocol": "UDP",
      "source": "HCX-NE in HA Group",
      "destination": "HCX NE in HA Group (same site)",
      "purpose": "HA Hearbeats",
      "serviceDescription": "Network Extension High Availability Bi-Directional Forwarding Detection (BFD)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92995",
      "port": "8182",
      "protocol": "TCP",
      "source": "HCX-NE in HA Group",
      "destination": "HCX NE in HA Group (same site)",
      "purpose": "HA Control",
      "serviceDescription": "Network Extension High Availability Control Traffic.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92996",
      "port": "31031",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Migration",
      "serviceDescription": "HCX Bulk Migration Un-encrypted.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92997",
      "port": "32032",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Migration",
      "serviceDescription": "HCX Bulk Migration Encrypted.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92998",
      "port": "902",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Migration Services",
      "serviceDescription": "Network File Copy (NFC) based Cold Migrations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323404aec70d0faf92999",
      "port": "443",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX)",
      "destination": "vCenter Server Management IP address",
      "purpose": "HCX Migration Services",
      "serviceDescription": "VPXA Listener.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf9299a",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "HCX Manager",
      "purpose": "HCX Service UI",
      "serviceDescription": "Configure and Manage HCX Services.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf9299b",
      "port": "9443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "HCX Manager",
      "purpose": "HCX Appliance Management Interface",
      "serviceDescription": "Activate and Register vCenter Server and Management Systems.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf9299c",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX vMotion Service",
      "serviceDescription": "HCX vMotion Control.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf9299d",
      "port": "8123",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Bulk Migration Control",
      "serviceDescription": "HCX Bulk Migration Control.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf9299e",
      "port": "9443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "Interconnect (HCX-IX), Network Extension (HCX-NE)",
      "purpose": "HCX Internal Control",
      "serviceDescription": "HCX Internal Control.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf9299f",
      "port": "80",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Service Mesh Deployment",
      "serviceDescription": "OVF Import / Service Appliance Deployment.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf929a0",
      "port": "902",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Service Mesh Deployment",
      "serviceDescription": "OVF Import / Service Appliance Deployment.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323414aec70d0faf929a1",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Migration Services",
      "serviceDescription": "Control traffic for HCX vMotion migration operations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323424aec70d0faf929a2",
      "port": "902",
      "protocol": "UDP",
      "source": "Interconnect (HCX-IX)",
      "destination": "vCenter Server Management IP address",
      "purpose": "HCX Migration Services",
      "serviceDescription": "HCX vMotion Control.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323424aec70d0faf929a3",
      "port": "80",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX)",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Migration Services",
      "serviceDescription": "ESX Authentication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323424aec70d0faf929a4",
      "port": "443",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX)",
      "destination": "ESX Management IP addresses",
      "purpose": "HCX Migration Services",
      "serviceDescription": "ESX Authentication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323424aec70d0faf929a5",
      "port": "8000",
      "protocol": "TCP",
      "source": "Interconnect (HCX-IX)",
      "destination": "ESX vMotion IP addresses",
      "purpose": "HCX Migration Services",
      "serviceDescription": "HCX vMotion Protocol.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323424aec70d0faf929a6",
      "port": "8000",
      "protocol": "TCP",
      "source": "ESX vMotion IP addresses",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Migration Services",
      "serviceDescription": "HCX vMotion Protocol.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323434aec70d0faf929a7",
      "port": "902",
      "protocol": "TCP",
      "source": "ESX Management IP addresses",
      "destination": "Interconnect (HCX-IX)",
      "purpose": "HCX Migration Services",
      "serviceDescription": "HCX Cold Migration (bidirectional)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323434aec70d0faf929a8",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager (Cloud)",
      "destination": "vCloud Director",
      "purpose": "HCX with vCloud Director Management",
      "serviceDescription": "vCloud Director API (Additional requirement at the Destination with vCloud Director-based installations)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323434aec70d0faf929a9",
      "port": "5672",
      "protocol": "TCP",
      "source": "HCX Manager (Cloud)",
      "destination": "AMQP/RabbitMQ Broker",
      "purpose": "HCX with vCloud Director Messaging",
      "serviceDescription": "Advanced Message Queue Protocol (Additional requirement at the Destination with vCloud Director-based installations)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323434aec70d0faf929aa",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations Management IP address",
      "destination": "HCX Manager",
      "purpose": "Monitoring HCX in VCF Operations Manager using MP",
      "serviceDescription": "Collection of HCX metrics for VCF Operations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323434aec70d0faf929ab",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Sentinel Agent on Virtual Machine",
      "destination": "Sentinel Gateway (HCX-SGW)",
      "purpose": "OSAM Data Transfer",
      "serviceDescription": "HCX Sentinel Agent Virtual Machine Data Transfer.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323434aec70d0faf929ac",
      "port": "9443",
      "protocol": "TCP",
      "source": "HCX Manager (Cloud/Destination)",
      "destination": "Sentinel Data Receiver (HCX-SDR",
      "purpose": "OSAM Service Management",
      "serviceDescription": "HCX Service Appliance Configuration and Control.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929ae",
      "port": "5140",
      "protocol": "UDP",
      "source": "Interconnect (HCX-IX)",
      "destination": "HCX Manager",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Syslog Originator to Syslog Forwarder.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b0",
      "port": "5140",
      "protocol": "UDP",
      "source": "HCX-NE",
      "destination": "HCX Manager",
      "purpose": "Common Infrastructure Management",
      "serviceDescription": "Syslog Originator to Syslog Forwarder.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b1",
      "port": "443",
      "protocol": "TCP",
      "source": "SDDC Manager Management IP address",
      "destination": "HCX Manager",
      "purpose": "LCM",
      "serviceDescription": "Used for HCX Deployment, Import and Upgrades.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b2",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks Management IP address",
      "destination": "HCX Manager",
      "purpose": "Migration Planning",
      "serviceDescription": "Used for persisting Migration Plans to HCX.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b3",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "HCX Manager",
      "purpose": "Log management",
      "serviceDescription": "Log management.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b4",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "License Server Management IP address",
      "purpose": "Licensing",
      "serviceDescription": "Licensing.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b5",
      "port": "443",
      "protocol": "TCP",
      "source": "HCX Manager",
      "destination": "VCF Identity Broker",
      "purpose": "VCF SSO Authentication",
      "serviceDescription": "VCF SSO Authentication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b6",
      "port": "8443",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "Web Service",
      "serviceDescription": "Inter-service communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323444aec70d0faf929b7",
      "port": "8085",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "Migration Planner Service",
      "serviceDescription": "Inter-service communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323454aec70d0faf929b8",
      "port": "8444",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "Appliance Management Service",
      "serviceDescription": "Inter-service communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323454aec70d0faf929b9",
      "port": "5432",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "Postgres Service",
      "serviceDescription": "Inter-service communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        },
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a0323454aec70d0faf929ba",
      "port": "2181",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "Zookeeper",
      "serviceDescription": "Inter-service communication.",
      "classification": "Both",
      "publishDate": "2026-08-30T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a0323454aec70d0faf929bb",
      "port": "9092",
      "protocol": "TCP",
      "source": "VCF Operations HCX (internal/loopback)",
      "destination": "VCF Operations HCX (internal/loopback)",
      "purpose": "Kafka",
      "serviceDescription": "Inter-service communication.",
      "classification": "Both",
      "publishDate": "2026-08-30T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a0322d24aec70d0faf92972",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a97be468a02c088cd7922bd",
      "port": "514",
      "protocol": "UDP",
      "source": "Interconnect (HCX-IX)",
      "destination": "HCX Manager",
      "purpose": "Syslog Originator to Syslog Forwarder.",
      "serviceDescription": "Common Infrastructure Management",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a97be468a02c088cd7922be",
      "port": "514",
      "protocol": "UDP",
      "source": "HCX-NE",
      "destination": "HCX Manager",
      "purpose": " Syslog Originator to Syslog Forwarder.",
      "serviceDescription": "Common Infrastructure Management",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations HCX",
      "productId": "68591a8148aeb10d5142cfc5",
      "releases": [
        {
          "id": "6a97bcc90a0f8afb34ca2eae",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cdf4aec70d0faf929bc",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations for Networks",
      "purpose": "SSH service",
      "serviceDescription": "SSH port, Secure remote access and command-line administration.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cdf4aec70d0faf929bd",
      "port": "22",
      "protocol": "TCP",
      "source": "LCM",
      "destination": "VCF Operations for Networks",
      "purpose": "SSH service",
      "serviceDescription": "Ops LCM connects to VON nodes for internal scripts execution.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cdf4aec70d0faf929be",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "SSH service",
      "serviceDescription": "VON nodes in cluster connects to each other to run operational commands.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cdf4aec70d0faf929bf",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ISR 4000",
      "purpose": "Cisco ISR Data source",
      "serviceDescription": "Cisco ISR 4000 data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cdf4aec70d0faf929c0",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ASR 1000",
      "purpose": "Cisco ASR Data source",
      "serviceDescription": "Cisco ASR 1000 data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce04aec70d0faf929c1",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ASR 9901/9910",
      "purpose": "Cisco ASR Data source",
      "serviceDescription": "Cisco ASR 9901/9910 data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce04aec70d0faf929c2",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Mellanox switch",
      "purpose": "Mellanox data source",
      "serviceDescription": "Mellanox data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce04aec70d0faf929c3",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Huawei 6800/7800/8800",
      "purpose": "Huawei data source",
      "serviceDescription": "Huawei 6800/7800/8800 data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce04aec70d0faf929c4",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "HP Virtual Connect Manager",
      "purpose": "HP data source",
      "serviceDescription": "HP Virtual Connect Manager SSH.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce04aec70d0faf929c5",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ASA",
      "purpose": "Cisco ASA data source",
      "serviceDescription": "Cisco ASA data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929c6",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Arista switch",
      "purpose": "Arista switches",
      "serviceDescription": "Arista switches: network device collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929c7",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Brocade Switch",
      "purpose": "Brocade switch Data source",
      "serviceDescription": "Brocade switches Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929c8",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Juniper Switch",
      "purpose": "Juniper switch Data source",
      "serviceDescription": "Juniper Switches Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929c9",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "HP Switch",
      "purpose": "HP data source",
      "serviceDescription": "HP Switch Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929ca",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Dell Switch",
      "purpose": "Dell Switch data source",
      "serviceDescription": "Dell switches Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929cb",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco Catalyst",
      "purpose": "Cisco Catalyst Data source",
      "serviceDescription": "Cisco Catalyst Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce14aec70d0faf929cc",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco Nexus",
      "purpose": "Cisco Nexus Data source",
      "serviceDescription": "Cisco Nexus Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce24aec70d0faf929cd",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco UCS",
      "purpose": "Cisco UCS Data source",
      "serviceDescription": "Cisco UCS Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce24aec70d0faf929ce",
      "port": "22",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Check Point firewall",
      "purpose": "Check point firewall data source",
      "serviceDescription": "Check Point firewall Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce24aec70d0faf929cf",
      "port": "53",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "DNS Resolvers",
      "purpose": "DNS resolution",
      "serviceDescription": "Outgoing from VON to DNS server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce24aec70d0faf929d0",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations for Networks",
      "purpose": "Application access",
      "serviceDescription": "HTTP clients to the platform (when port 80 is used; many deployments use 443 only).",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce34aec70d0faf929d1",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "NTP Server",
      "purpose": "Host Time Synchronization (NTP)",
      "serviceDescription": "Outgoing from VON to NTP server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce34aec70d0faf929d2",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "F5 BIG-IP",
      "purpose": "F5 BIG- IP Data source",
      "serviceDescription": "F5 BIG-IP data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce34aec70d0faf929d3",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ACI",
      "purpose": "Cisco ACI Data source",
      "serviceDescription": "Cisco ACI Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce34aec70d0faf929d4",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ISR 4000",
      "purpose": "Cisco ISR Data source",
      "serviceDescription": "Cisco ISR 4000 data collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce34aec70d0faf929d5",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ASR 1000",
      "purpose": "Cisco ASR Data source",
      "serviceDescription": "Cisco ASR 1000 data collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce34aec70d0faf929d6",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ASR 9901/9910",
      "purpose": "Cisco ASR Data source",
      "serviceDescription": "Cisco ASR 9901/9910 SNMP.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce44aec70d0faf929d7",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Mellanox switch",
      "purpose": "Mellanox data source",
      "serviceDescription": "Mellanox data collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce44aec70d0faf929d8",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Huawei 6800/7800/8800",
      "purpose": "Huawei data source",
      "serviceDescription": "Huawei 6800/7800/8800 SNMP.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce44aec70d0faf929d9",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ASA",
      "purpose": "Cisco ASA data source",
      "serviceDescription": "Cisco ASA data collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce44aec70d0faf929da",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Arista switch",
      "purpose": "Arista switches",
      "serviceDescription": "Arista switches Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce44aec70d0faf929db",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Brocade Switch",
      "purpose": "Brocade switch Data source",
      "serviceDescription": "Brocade switches Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce54aec70d0faf929dc",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Juniper Switch",
      "purpose": "Juniper switch Data source",
      "serviceDescription": "Juniper Switches Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce54aec70d0faf929dd",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Dell Switch",
      "purpose": "Dell Switch data source",
      "serviceDescription": "Dell switches Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce54aec70d0faf929de",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco Catalyst",
      "purpose": "Cisco Catalyst Data source",
      "serviceDescription": "Cisco Catalyst Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce54aec70d0faf929df",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco Nexus",
      "purpose": "Cisco Nexus Data source",
      "serviceDescription": "Cisco Nexus Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce54aec70d0faf929e0",
      "port": "161",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco UCS",
      "purpose": "Cisco UCS Data source",
      "serviceDescription": "Cisco UCS Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce64aec70d0faf929e1",
      "port": "162",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "SNMP Management System",
      "purpose": "SNMP",
      "serviceDescription": "SNMP trap collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce64aec70d0faf929e2",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations for Networks",
      "purpose": "User HTTPS traffic",
      "serviceDescription": "HTTPS port for application access via UI.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce64aec70d0faf929e3",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Azure NSX Manager",
      "purpose": "Azure NSX Manager Data source",
      "serviceDescription": "Data Collection from Azure NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce64aec70d0faf929e4",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "F5 BIG-IP",
      "purpose": "F5 BIG- IP Data source",
      "serviceDescription": "F5 BIG-IP data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce64aec70d0faf929e5",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Google Cloud NSX Manager",
      "purpose": "Google Cloud NSX Manager Data source",
      "serviceDescription": "Data Collection from Google Cloud NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce74aec70d0faf929e6",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Dell EMC NSX Manager",
      "purpose": "Dell EMC NSX Manager Datasource",
      "serviceDescription": "Dell EMC NSX Manager data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce74aec70d0faf929e7",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "AWS Outposts NSX Manager",
      "purpose": "VMC Data source",
      "serviceDescription": "Data Collection from VMC on AWS Outposts NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce74aec70d0faf929e8",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "AWS NSX Manager",
      "purpose": "VMC Data source",
      "serviceDescription": "Data Collection from VMC on AWS NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce84aec70d0faf929e9",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "NSX Manager",
      "purpose": "NSX-T Data source",
      "serviceDescription": "Network Communication (NSX-T)",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce84aec70d0faf929ea",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Infoblox",
      "purpose": "Infoblox data source",
      "serviceDescription": "Infoblox data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce84aec70d0faf929eb",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "ServiceNow",
      "purpose": "ServiceNow Data source",
      "serviceDescription": "ServiceNow data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce84aec70d0faf929ec",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Logs Management IP address",
      "destination": "VCF Operations for Networks",
      "purpose": "Log Insight",
      "serviceDescription": "Log Insight push notification.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce94aec70d0faf929ed",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco ACI",
      "purpose": "Cisco ACI Data source",
      "serviceDescription": "Cisco ACI: REST/HTTPS data collection to API.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce94aec70d0faf929ee",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "AWS Services",
      "purpose": "AWS connections",
      "serviceDescription": "AWS Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ce94aec70d0faf929ef",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "HP One view",
      "purpose": "HP data source",
      "serviceDescription": "HP One View Manager data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cea4aec70d0faf929f0",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Avi Controller",
      "purpose": "NSX-ALB data source",
      "serviceDescription": "NSX-ALB data source collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cea4aec70d0faf929f1",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Long poll connection",
      "serviceDescription": "Collector to Platform primary channel.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cea4aec70d0faf929f2",
      "port": "443",
      "protocol": "TCP",
      "source": "Webhook from NSX",
      "destination": "VCF Operations for Networks",
      "purpose": "Webhook",
      "serviceDescription": "Webhook connections from NSX.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ceb4aec70d0faf929f3",
      "port": "443",
      "protocol": "TCP",
      "source": "Webhook from ServiceNow",
      "destination": "VCF Operations for Networks",
      "purpose": "Webhook",
      "serviceDescription": "Webhook connections from ServiceNow.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ceb4aec70d0faf929f4",
      "port": "443",
      "protocol": "TCP",
      "source": "Webhook from VCF Operations for Logs",
      "destination": "VCF Operations for Networks",
      "purpose": "Webhook",
      "serviceDescription": "Webhook connections from LI.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cec4aec70d0faf929f5",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Oracle Cloud NSX Manager",
      "purpose": "Oracle Cloud NSX Manager data source",
      "serviceDescription": "Oracle Cloud NSX Manager data collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cec4aec70d0faf929f6",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "ESX Management IP addresses",
      "purpose": "vSphere Data source",
      "serviceDescription": "VMware vSphere Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cec4aec70d0faf929f7",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Palo Alto Networks",
      "purpose": "Palo Alto Networks Data source",
      "serviceDescription": "Palo Alto Networks Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ced4aec70d0faf929f8",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Cisco UCS",
      "purpose": "Cisco UCS Data source",
      "serviceDescription": "Cisco UCS Network Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032ced4aec70d0faf929f9",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Check Point firewall",
      "purpose": "Check point firewall data source",
      "serviceDescription": "Check Point firewall Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cee4aec70d0faf929fa",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Fortinet FortiManager",
      "purpose": "Fortinet Data source",
      "serviceDescription": "Fortinet FortiManager Communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cee4aec70d0faf929fb",
      "port": "443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "VCF Operations HCX Management IP address",
      "purpose": "HCX data source",
      "serviceDescription": "HCX.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cee4aec70d0faf929fc",
      "port": "443",
      "protocol": "TCP",
      "source": "LCM",
      "destination": "VCF Operations for Networks",
      "purpose": "LCM integration",
      "serviceDescription": "LCM service to VON nodes for various integrations.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cef4aec70d0faf929fd",
      "port": "803",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Juniper Switch",
      "purpose": "Juniper Switch Datasource",
      "serviceDescription": "Juniper Switch Datasource.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cef4aec70d0faf929fe",
      "port": "2055",
      "protocol": "UDP",
      "source": "ESX Management IP addresses",
      "destination": "VCF Operations for Networks",
      "purpose": "IPFIX service",
      "serviceDescription": "IPFIX.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cef4aec70d0faf929ff",
      "port": "2095",
      "protocol": "TCP",
      "source": "VKS gRPC server",
      "destination": "VCF Operations for Networks",
      "purpose": "Antrea CNI Data source",
      "serviceDescription": "Receives Network Flow data from Antrea CNI.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cef4aec70d0faf92a00",
      "port": "2181",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "ZooKeeper (client and coordination)",
      "serviceDescription": "ZooKeeper client port; services (Kafka, YARN RM HA, HDFS ZKFC) use the ensemble on platform nodes.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cef4aec70d0faf92a01",
      "port": "2191",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "Avi Controller",
      "purpose": "NSX-ALB data source",
      "serviceDescription": "NSX-ALB Flow collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf04aec70d0faf92a02",
      "port": "2888",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "ZooKeeper",
      "serviceDescription": "ZooKeeper peer communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf04aec70d0faf92a03",
      "port": "3000",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Node JS server",
      "serviceDescription": "VCF Operations for Networks: Node.js admin stack on platform.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf04aec70d0faf92a04",
      "port": "3055",
      "protocol": "TCP",
      "source": "NSX MetricServer Grpc service",
      "destination": "VCF Operations for Networks",
      "purpose": "gRPC service",
      "serviceDescription": "NSXMetricServer Grpc service.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf04aec70d0faf92a05",
      "port": "3095",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "VKS gRPC server",
      "purpose": "gRPC",
      "serviceDescription": "VKS cluster communication through the gRPC tunnel.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf04aec70d0faf92a06",
      "port": "3100",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Operations for Networks",
      "purpose": "Nginx / application entry",
      "serviceDescription": "Nginx and upstream to local application tier.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf04aec70d0faf92a07",
      "port": "3888",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Zookeeper",
      "serviceDescription": "ZooKeeper leader election.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a08",
      "port": "4406",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "NTS",
      "purpose": "NTS",
      "serviceDescription": "Secure NTP Service (NTS)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a09",
      "port": "4443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Registration server",
      "serviceDescription": "External proxy tunnel Registration.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a0a",
      "port": "6060",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Federation service",
      "serviceDescription": "Federation service primary/peer.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a0b",
      "port": "6343",
      "protocol": "UDP",
      "source": "VCF Operations for Networks",
      "destination": "SFlow",
      "purpose": "Sflow",
      "serviceDescription": "SFlow Network Communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a0c",
      "port": "7071",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Upgrade server",
      "serviceDescription": "Web Server (Nginx) Local proxy Upgrade.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a0d",
      "port": "7072",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Telemetry service",
      "serviceDescription": "Web Server (Nginx) - Telemetry OFF.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf14aec70d0faf92a0e",
      "port": "7074",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Telemetry service",
      "serviceDescription": "Web Server (Nginx) - Telemetry metrics.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf24aec70d0faf92a0f",
      "port": "8003",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Databus gateway",
      "serviceDescription": "Platform and collector connect to the Databus gateway.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf24aec70d0faf92a10",
      "port": "8008",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Patroni service",
      "serviceDescription": "Patroni Service HA postgres.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf24aec70d0faf92a11",
      "port": "8019",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Zookeeper",
      "serviceDescription": "HDFS ZooKeeper FailoverController.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf24aec70d0faf92a12",
      "port": "8020",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS NameNode RPC",
      "serviceDescription": "HDFS namespace and metadata.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf24aec70d0faf92a13",
      "port": "8025",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN ResourceManager: resource tracker",
      "serviceDescription": "RM resource tracker.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf34aec70d0faf92a14",
      "port": "8030",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN ResourceManager: scheduler",
      "serviceDescription": "RM scheduler interface.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf34aec70d0faf92a15",
      "port": "8031",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN Resource Manager",
      "serviceDescription": "Hadoop Yarn Resource Manager.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf34aec70d0faf92a16",
      "port": "8032",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN ResourceManager: web UI / client service",
      "serviceDescription": "RM address WebApp/SC.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf34aec70d0faf92a17",
      "port": "8033",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN Resource Manager",
      "serviceDescription": "RM admin interface (Platform Setup)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf34aec70d0faf92a18",
      "port": "8040",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN Node Manager",
      "serviceDescription": "Hadoop Yarn Node Manager.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf34aec70d0faf92a19",
      "port": "8042",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Node Manager",
      "serviceDescription": "Node manager web app address.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf44aec70d0faf92a1a",
      "port": "8080",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "REST API (application)",
      "serviceDescription": "Primary REST API (restapi);.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf44aec70d0faf92a1b",
      "port": "8081",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "REST API sevice",
      "serviceDescription": "REST API Service.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf44aec70d0faf92a1c",
      "port": "8088",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "YARN ResourceManager: HTTP/REST and UI",
      "serviceDescription": "RM health/UI.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf44aec70d0faf92a1d",
      "port": "8091",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Platform support service",
      "serviceDescription": "Document actual listener (e.g. VIP/health)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf44aec70d0faf92a1e",
      "port": "8123",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "VCF Operations for Networks",
      "purpose": "NSX Webhook",
      "serviceDescription": "Webhook for NSX data source.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf44aec70d0faf92a1f",
      "port": "8124",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "VCF Operations for Networks",
      "purpose": "NSX Webhook",
      "serviceDescription": "Webhook for NSX data source.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a20",
      "port": "8126",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Datadog service",
      "serviceDescription": "Datadog-agent APM Receiver.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a21",
      "port": "8155",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "gRPC",
      "serviceDescription": "Secure tunnel between the gRPC server and localhost on Collector.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a22",
      "port": "8443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "TKGI API Server",
      "purpose": "TKGI API Server",
      "serviceDescription": "TKGI API Server communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a23",
      "port": "8443",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Kubernetes/Openshift Cluster",
      "purpose": "Openshift",
      "serviceDescription": "Kubernetes/Openshift Cluster collection.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a24",
      "port": "8480",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS JournalNode: HTTP (typical)",
      "serviceDescription": "JournalNode web/admin;.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a25",
      "port": "8485",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS JournalNode: Quorum (edits, RPC)",
      "serviceDescription": "Quorum journal protocol.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a26",
      "port": "9000",
      "protocol": "UDP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "SNMP",
      "serviceDescription": "SNMP trap collection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a27",
      "port": "9090",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Collector Nginx",
      "serviceDescription": "Proxy port on Nginx for collector to platform communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a28",
      "port": "9091",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Saas Service",
      "serviceDescription": "SAAS Service.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf54aec70d0faf92a29",
      "port": "9092",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Apache Kafka (broker API)",
      "serviceDescription": "Kafka client/broker.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a2a",
      "port": "9300",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Elastic search service",
      "serviceDescription": "Elasticsearch nodes communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a2b",
      "port": "9543",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "VCF Operations for Logs Management IP address",
      "purpose": "Log Insight",
      "serviceDescription": "VON collector to LI.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a2c",
      "port": "9864",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Data node",
      "serviceDescription": "HDFS Datanode HTTP server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a2d",
      "port": "9865",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFC Data node",
      "serviceDescription": "HDFS Datanode HTTPS server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a2e",
      "port": "9866",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Data node",
      "serviceDescription": "HDFS Datanode data transfer.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a2f",
      "port": "9867",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Data node",
      "serviceDescription": "HDFS Datanode ipc server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a30",
      "port": "9868",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Name Node",
      "serviceDescription": "HDFS Namenode secondary HTTP.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a31",
      "port": "9869",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Name Node",
      "serviceDescription": "HDFS Namenode secondary HTTPS.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a32",
      "port": "9870",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Name Node",
      "serviceDescription": "HDFS Namenode HTTP server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a33",
      "port": "10001",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Localization service",
      "serviceDescription": "Localization Service.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a34",
      "port": "10101",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HMaster",
      "serviceDescription": "Hbase Master JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a35",
      "port": "10102",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Hbase Region server",
      "serviceDescription": "Hbase Region Server JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf64aec70d0faf92a36",
      "port": "11100",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "JMX",
      "serviceDescription": "SAAS Service JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a37",
      "port": "11101",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "REST API service (JMX)",
      "serviceDescription": "RestApi service JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a38",
      "port": "11108",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Launcher service",
      "serviceDescription": "Launcher service JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a39",
      "port": "11114",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFC Data node",
      "serviceDescription": "HDFS Datanode JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a3a",
      "port": "11115",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HDFS Node Node",
      "serviceDescription": "HDFS Namenode JMX Port.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a3b",
      "port": "13562",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Auxiliary listener (e.g. Spark/YARN NM site-specific, verify)",
      "serviceDescription": "Auxiliary listener (e.g. Spark/YARN NM site-specific, verify)",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a3c",
      "port": "16000",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "HBase Master (RPC)",
      "serviceDescription": "HBase master RPC; regionservers often 16020.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a3d",
      "port": "16020",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Hbase Region server",
      "serviceDescription": "HBase RegionServer connection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a3e",
      "port": "16030",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Hbase Region server",
      "serviceDescription": "HBase RegionServer connection.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a3f",
      "port": "25333",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Py4J",
      "serviceDescription": "Py4J Config Store Search API.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a40",
      "port": "47500",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "gRPC service",
      "serviceDescription": "Path Analyzer GRPC server.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a41",
      "port": "50000",
      "protocol": "TCP",
      "source": "Dell OS 10",
      "destination": "VCF Operations for Networks",
      "purpose": "Dell OS10 Datasource",
      "serviceDescription": "Dell OS10 Network Communication.",
      "classification": "Inbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a42",
      "port": "50055",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Analytics service",
      "serviceDescription": "Day2Ops analytics service.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a43",
      "port": "55111",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Metric cache service",
      "serviceDescription": "Metric Cache Service.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a44",
      "port": "55112",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "REST API sevice",
      "serviceDescription": "REST API Service internal compute.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf74aec70d0faf92a45",
      "port": "389",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP",
      "serviceDescription": "LDAP server communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a46",
      "port": "636",
      "protocol": "TCP",
      "source": "VCF Operations for Networks",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP",
      "serviceDescription": "LDAP server communication.",
      "classification": "Outbound",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a47",
      "port": "4500-4510",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Foundation DB service",
      "serviceDescription": "Foundation DB servers communication.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a48",
      "port": "9200-9299",
      "protocol": "TCP",
      "source": "VCF Operations for Networks (internal/loopback)",
      "destination": "VCF Operations for Networks (internal/loopback)",
      "purpose": "Elastic search service",
      "serviceDescription": "Elasticsearch search requests.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a49",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations for Networks",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Networks and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a4a",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations for Networks",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Networks and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a4b",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "VCF Operations for Networks",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Networks and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a032cf84aec70d0faf92a4c",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "VCF Operations for Networks",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between VCF Operations for Networks and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a0324c95887ef2531709a6b",
          "name": "9.1.0"
        },
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a9fa4dd4a973bfa11ce164e",
      "port": "3095",
      "protocol": "TCP",
      "source": "VKS (vSphere Kubernetes Service) cluster",
      "destination": "Collector",
      "purpose": "grpc-vks-server (gRPC telemetry endpoint, mTLS)",
      "serviceDescription": "[Best-effort, derived from live process inspection, not product docs] Collector receives telemetry data pushed from VKS clusters over gRPC",
      "classification": "N/A",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a9fa4dd4a973bfa11ce164f",
      "port": "8155",
      "protocol": "TCP",
      "source": "Localhost",
      "destination": "Collector",
      "purpose": "grpc-vks-server internal proxy target for port 3095",
      "serviceDescription": "Collecto[Best-effort, derived from live process inspection, not product docs] Internal loopback-only port used by grpc-vks-server to forward traffic from port 3095",
      "classification": "N/A",
      "publishDate": "2026-09-05T00:00:00Z",
      "product": "VCF Operations for Networks",
      "productId": "6405a239c3f9fc6c492d9029",
      "releases": [
        {
          "id": "6a9fa35e4a973bfa11ce15bc",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c1fa",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "DSM Provider Management IP address",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into the DSM Provider/Appliance.",
      "classification": "Inbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c1fb",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "DSM Provider Management IP address",
      "purpose": "DSM UI / API",
      "serviceDescription": "DSM Provider/Appliance web UI and REST API over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c1fc",
      "port": "123",
      "protocol": "UDP",
      "source": "DSM Provider Management IP address",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for the DSM Provider/Appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c1fd",
      "port": "53",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from the DSM Provider/Appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c1fe",
      "port": "53",
      "protocol": "UDP",
      "source": "DSM Provider Management IP address",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from the DSM Provider/Appliance.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c1ff",
      "port": "443",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter integration",
      "serviceDescription": "DSM Provider connects to vCenter for VM and storage operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c200",
      "port": "443",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "ESX integration",
      "serviceDescription": "DSM Provider connects to ESX hosts for VM operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c201",
      "port": "902",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "ESX Management IP addresses",
      "purpose": "OVA deployment",
      "serviceDescription": "DSM Provider uses 902 to deploy OVA templates to ESX hosts.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c202",
      "port": "443",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Supervisor (VKS) Management IP address",
      "purpose": "Supervisor integration",
      "serviceDescription": "DSM Provider connects to the Supervisor (VKS) control plane.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c669044725e5fb7c203",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "S3-compatible Storage",
      "purpose": "Object storage (backups/logs)",
      "serviceDescription": "DSM Provider outbound data traffic to S3-compatible storage for backups and logs. Port is configurable.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c204",
      "port": "3269",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS Global Catalog (AD)",
      "serviceDescription": "Secure LDAP Global Catalog integration. Port is configurable.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c205",
      "port": "636",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "Secure LDAP integration. Port is configurable.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c206",
      "port": "514",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Syslog Servers",
      "purpose": "Syslog",
      "serviceDescription": "DSM Provider syslog forwarding to a syslog destination (VCF Operations for Logs or other SIEM).",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c207",
      "port": "443",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "VCF Automation Management IP address",
      "purpose": "VCF Automation integration",
      "serviceDescription": "DSM Provider integration with VCF Automation.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c208",
      "port": "8443",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Metrics forwarding",
      "serviceDescription": "DSM Provider forwards metrics through the VCF Operations Cloud Proxy.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c209",
      "port": "9090",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Prometheus Remote Write Server",
      "purpose": "Prometheus remote write",
      "serviceDescription": "DSM Provider forwards metrics to a Prometheus remote-write endpoint. Port is configurable.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c20a",
      "port": "25",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Email Server",
      "purpose": "SMTP",
      "serviceDescription": "DSM Provider sends email via SMTP. Configurable; can use 25, 587, or another port.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c679044725e5fb7c20b",
      "port": "587",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Email Server",
      "purpose": "SMTP submission",
      "serviceDescription": "DSM Provider sends email via SMTP submission (authenticated). Configurable.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c20c",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Webhook Server (external)",
      "purpose": "Webhook notifications",
      "serviceDescription": "DSM Provider sends notification payloads to a customer-configured webhook server. Port is configurable.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c20d",
      "port": "22",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "DSM Database Cluster Node",
      "purpose": "SSH to DB cluster",
      "serviceDescription": "DSM Provider SSH access to Database cluster nodes for system operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c20e",
      "port": "5432",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "DSM Database Cluster Node",
      "purpose": "Postgres DR",
      "serviceDescription": "Postgres disaster recovery flow between the DSM Provider and Database cluster.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c20f",
      "port": "6443",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "DSM Database Cluster Node",
      "purpose": "Kubernetes API",
      "serviceDescription": "Kubernetes API requests from the DSM Provider to Database cluster nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c210",
      "port": "2379",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "etcd (cluster)",
      "serviceDescription": "Internal etcd traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c211",
      "port": "2380",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "etcd peer (cluster)",
      "serviceDescription": "Internal etcd peer traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c212",
      "port": "6443",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "Kubernetes API (cluster)",
      "serviceDescription": "Internal Kubernetes API traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c689044725e5fb7c213",
      "port": "6081",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "Cluster overlay",
      "serviceDescription": "Inter-node overlay traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c214",
      "port": "10349",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "Cluster health sync",
      "serviceDescription": "Internal health sync between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c215",
      "port": "10351",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "Cluster comms",
      "serviceDescription": "Internal clustering traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c216",
      "port": "10351",
      "protocol": "UDP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "Cluster comms",
      "serviceDescription": "Internal clustering traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c217",
      "port": "5432",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "Postgres DR (cluster)",
      "serviceDescription": "Postgres replication for disaster recovery between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c218",
      "port": "3306",
      "protocol": "TCP",
      "source": "DSM Database Cluster (internal)",
      "destination": "DSM Database Cluster (internal)",
      "purpose": "MySQL replication (cluster)",
      "serviceDescription": "MySQL read replica traffic between Database cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c219",
      "port": "user-configurable",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "S3-compatible Storage",
      "purpose": "Object storage (backups/logs)",
      "serviceDescription": "Database cluster outbound data traffic to S3-compatible storage for backups and logs.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c21a",
      "port": "443",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter integration",
      "serviceDescription": "Database cluster nodes connect to vCenter for VM operations.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c699044725e5fb7c21b",
      "port": "123",
      "protocol": "UDP",
      "source": "DSM Database Cluster Node",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for Database cluster nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c21c",
      "port": "53",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from Database cluster nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c21d",
      "port": "53",
      "protocol": "UDP",
      "source": "DSM Database Cluster Node",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from Database cluster nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c21e",
      "port": "514",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Syslog Servers",
      "purpose": "Syslog",
      "serviceDescription": "Database cluster syslog forwarding to a syslog destination.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c21f",
      "port": "443",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "DSM Provider Management IP address",
      "purpose": "Image / metrics back to DSM Provider",
      "serviceDescription": "Database cluster nodes pull images and forward metrics to the DSM Provider.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c220",
      "port": "3269",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS Global Catalog (AD)",
      "serviceDescription": "Secure LDAP Global Catalog integration from Database cluster nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c221",
      "port": "636",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "Secure LDAP integration from Database cluster nodes.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c222",
      "port": "8443",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "VCF Operations Cloud Proxy",
      "purpose": "Metrics forwarding",
      "serviceDescription": "Database cluster metrics forwarded through the VCF Operations Cloud Proxy.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c223",
      "port": "9090",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Prometheus Remote Write Server",
      "purpose": "Prometheus remote write",
      "serviceDescription": "Database cluster metrics forwarded to a Prometheus remote-write endpoint.",
      "classification": "Outbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6a9044725e5fb7c224",
      "port": "5432",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "DSM Database Cluster Node",
      "purpose": "User Postgres access",
      "serviceDescription": "End-user access to a Postgres database service on a DSM Database cluster node.",
      "classification": "Inbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6b9044725e5fb7c225",
      "port": "3306",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "DSM Database Cluster Node",
      "purpose": "User MySQL access",
      "serviceDescription": "End-user access to a MySQL database service on a DSM Database cluster node.",
      "classification": "Inbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6b9044725e5fb7c226",
      "port": "1433",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "DSM Database Cluster Node",
      "purpose": "User SQL Server access",
      "serviceDescription": "End-user access to a SQL Server database service on a DSM Database cluster node.",
      "classification": "Inbound",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6b9044725e5fb7c227",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "DSM Provider Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the DSM Provider and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6b9044725e5fb7c228",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "DSM Provider Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the DSM Provider and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6b9044725e5fb7c229",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "DSM Provider Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the DSM Provider and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a045c6b9044725e5fb7c22a",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "DSM Provider Management IP address",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the DSM Provider and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-10T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b35",
      "port": "3268",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP Global Catalog (AD)",
      "serviceDescription": "Active Directory Domain Services Global Catalog",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b36",
      "port": "389",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "Active Directory Domain Services",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b37",
      "port": "389",
      "protocol": "UDP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "CLDAP (AD)",
      "serviceDescription": "Active Directory Domain Services",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b38",
      "port": "88",
      "protocol": "TCP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "Kerberos (AD)",
      "serviceDescription": "Kerberos Key Distribution Center (KDC)",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b39",
      "port": "88",
      "protocol": "UDP",
      "source": "DSM Provider Management IP address",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "Kerberos (AD)",
      "serviceDescription": "Kerberos Key Distribution Center (KDC)",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b3a",
      "port": "3268",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP Global Catalog (AD)",
      "serviceDescription": "Active Directory Domain Services Global Catalog",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b3b",
      "port": "389",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "Active Directory Domain Services",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b3c",
      "port": "389",
      "protocol": "UDP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "CLDAP (AD)",
      "serviceDescription": "Active Directory Domain Services",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b3d",
      "port": "88",
      "protocol": "TCP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "Kerberos (AD)",
      "serviceDescription": "Kerberos Key Distribution Center (KDC)",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a73201d28e5d2932fc84b3e",
      "port": "88",
      "protocol": "UDP",
      "source": "DSM Database Cluster Node",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "Kerberos (AD)",
      "serviceDescription": "Kerberos Key Distribution Center (KDC)",
      "classification": "Outbound",
      "publishDate": "2026-08-02T00:00:00Z",
      "product": "DSM Data Services",
      "productId": "6a045b144e349d6d9c172445",
      "releases": [
        {
          "id": "6a045b979044725e5fb7c1f9",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a05a3439044725e5fb7c22c",
      "port": "22",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "License Hub Node IP Pool",
      "purpose": "SSH",
      "serviceDescription": "ssh from SSP Installer node",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c22d",
      "port": "443",
      "protocol": "TCP",
      "source": "Management clients",
      "destination": "SSP Installer",
      "purpose": "HTTPS",
      "serviceDescription": "Main entry point for SSP Installer clients (UI etc)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c22e",
      "port": "22",
      "protocol": "TCP",
      "source": "Management clients",
      "destination": "SSP Installer",
      "purpose": "SSH",
      "serviceDescription": "Management clients ssh access to SSP Installer (if SSH activated)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c22f",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "SSP Installer",
      "destination": "DNS server",
      "purpose": "DNS",
      "serviceDescription": "DNS connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c230",
      "port": "123",
      "protocol": "UDP",
      "source": "SSP Installer",
      "destination": "NTP Servers",
      "purpose": "NTP",
      "serviceDescription": "NTP connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c231",
      "port": "22",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "License Hub Node IP Pool",
      "purpose": "SSH",
      "serviceDescription": "Pre-check VM deployment",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c232",
      "port": "6443",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "License Hub Node IP Pool",
      "purpose": "kube-apiserver",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c233",
      "port": "6443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "kube-apiserver",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c234",
      "port": "22",
      "protocol": "TCP",
      "source": "Management clients",
      "destination": "License Hub Node IP Pool",
      "purpose": "SSH",
      "serviceDescription": "Management clients ssh access to License Hub Nodes (if direct SSH is required)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3449044725e5fb7c235",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "SSP Installer",
      "purpose": "HTTPS",
      "serviceDescription": "Download images from SSP Installer registry",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c236",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "License Hub Node IP Pool",
      "destination": "DNS server",
      "purpose": "DNS",
      "serviceDescription": "DNS connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c237",
      "port": "123",
      "protocol": "UDP",
      "source": "License Hub Node IP Pool",
      "destination": "NTP Servers",
      "purpose": "NTP",
      "serviceDescription": "NTP connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c238",
      "port": "443",
      "protocol": "TCP",
      "source": "Management clients",
      "destination": "Service IP Pool first IP",
      "purpose": "HTTPS",
      "serviceDescription": "License Hub inbound ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c239",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "vCenter",
      "purpose": "HTTPS",
      "serviceDescription": "SSP Installer to vCenter",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c23a",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "vCenter",
      "purpose": "HTTPS",
      "serviceDescription": "CSI controller to vCenter",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c23b",
      "port": "514",
      "protocol": "UDP",
      "source": "License Hub Node IP Pool",
      "destination": "Syslog server",
      "purpose": "Syslog",
      "serviceDescription": "Syslog output (if configured)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c23c",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "vCenter",
      "purpose": "HTTPS",
      "serviceDescription": "License Hub outbound vCenter",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c23d",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "NSX Manager",
      "purpose": "HTTPS",
      "serviceDescription": "License Hub outbound NSX Manager",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c23e",
      "port": "389 / 636 / 3268 / 3269",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "LDAP (server)",
      "purpose": "LDAP / LDAPS",
      "serviceDescription": "License Hub outbound",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3459044725e5fb7c23f",
      "port": "2379",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "kube-apiserver -> etcd",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c240",
      "port": "2380",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "etcd cluster",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c241",
      "port": "10250",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "API Server -> kubelet",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c242",
      "port": "10256-10257",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "kube-controller-manager health check",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c243",
      "port": "10259",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "kube-proxy health check",
      "serviceDescription": "License Hub controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c244",
      "port": "8091",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "Antrea Health check",
      "serviceDescription": "License Hub Antrea controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c245",
      "port": "10349-10351",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "Antrea API server & metrics",
      "serviceDescription": "License Hub Antrea controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c246",
      "port": "6081",
      "protocol": "UDP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "Geneve tunnel",
      "serviceDescription": "Antrea tunnel (geneve)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c247",
      "port": "2112",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "Kube-vip health check",
      "serviceDescription": "License Hub controller kube-vip",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3469044725e5fb7c248",
      "port": "7946",
      "protocol": "TCP/UDP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "Metallb speaker quorum",
      "serviceDescription": "License Hub metallb",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c249",
      "port": "9808",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "License Hub Node IP Pool",
      "purpose": "CSI Health",
      "serviceDescription": "vmware csi",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c24a",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "access.broadcom.com",
      "purpose": "Required for authentication in case of connected mode deployments.",
      "serviceDescription": "License Hub to Broadcom IDP authentication",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c24b",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "prod-cdn-downloads.pulse.broadcom.com",
      "purpose": "Required for License Hub to download secure license files from Avi Cloud console for connected mode deployments.",
      "serviceDescription": "License downloads",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c24c",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "prod-cdn-uploads.pulse.broadcom.com",
      "purpose": "Required for License Hub to upload usage to Avi Cloud Console in connected mode deployments.",
      "serviceDescription": "License usage upload",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c24d",
      "port": "443",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "portal.pulse.broadcom.com",
      "purpose": "Required for reporting usage and getting entitlement in connected mode deployments",
      "serviceDescription": "License Hub communication to receive licenses",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c24e",
      "port": "3260 (iSCSI) 2049 (NFS)",
      "protocol": "TCP",
      "source": "License Hub Node IP Pool",
      "destination": "ESXi server hosting the shared storage",
      "purpose": "Shared Storage",
      "serviceDescription": "Worker node to vsphere datastore",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c24f",
      "port": "9092",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "License Hub Service IP Pool",
      "purpose": "config sync",
      "serviceDescription": "License Hub inbound kafka",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c250",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "License Hub Service IP Pool 1st IP address",
      "purpose": "Metrics",
      "serviceDescription": "License Hub inbound Ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a05a3479044725e5fb7c251",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Manager",
      "destination": "License Hub Service IP Pool 1st IP address",
      "purpose": "Licensing Client Service",
      "serviceDescription": "License Hub inbound Ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a05a2d59044725e5fb7c22b",
          "name": "5.1.2"
        }
      ]
    },
    {
      "id": "6a87d8ed28e5d2932fc84b99",
      "port": "443\t",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "registry.k8s.io",
      "purpose": "Fetch core DNS image",
      "serviceDescription": "Download CoreDNS which is needed for SSP Pod Communication",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b1bc90690c64533913",
      "port": "22",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "SSP Node IP Pool",
      "purpose": "SSH",
      "serviceDescription": "ssh from SSP Installer node",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b1bc90690c64533914",
      "port": "443",
      "protocol": "TCP",
      "source": "Mgmt clients",
      "destination": "SSP Installer",
      "purpose": "HTTPS",
      "serviceDescription": "Main entry point for SSP Installer clients (UI etc)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533915",
      "port": "22",
      "protocol": "TCP",
      "source": "Mgmt clients",
      "destination": "SSP Installer",
      "purpose": "SSH",
      "serviceDescription": "Mgmt clients ssh access to SSP Installer (if SSH activated)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533916",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "SSP Installer",
      "destination": "DNS server",
      "purpose": "DNS",
      "serviceDescription": "DNS connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533917",
      "port": "123",
      "protocol": "UDP",
      "source": "SSP Installer",
      "destination": "NTP Servers",
      "purpose": "NTP",
      "serviceDescription": "NTP connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533918",
      "port": "22",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "SSP Node IP Pool",
      "purpose": "SSH",
      "serviceDescription": "Pre-check VM deployment",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533919",
      "port": "6443",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "SSP Node IP Pool",
      "purpose": "kube-apiserver",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c6453391a",
      "port": "6443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "kube-apiserver",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c6453391b",
      "port": "22",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "SFTP backup server",
      "purpose": "SFTP",
      "serviceDescription": "Backup & Restore (if configured) Support Bundle (if configured)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c6453391c",
      "port": "22",
      "protocol": "TCP",
      "source": "Mgmt clients",
      "destination": "SSP Node IP Pool",
      "purpose": "SSH",
      "serviceDescription": "Mgmt clients ssh access to SSP Nodes (if direct SSH is required)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c6453391d",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Installer",
      "purpose": "HTTPS",
      "serviceDescription": "Download images from SSP Installer registry",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c6453391e",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "SSP Node IP Pool",
      "destination": "DNS server",
      "purpose": "DNS",
      "serviceDescription": "DNS connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c6453391f",
      "port": "123",
      "protocol": "UDP",
      "source": "SSP Node IP Pool",
      "destination": "NTP Servers",
      "purpose": "NTP",
      "serviceDescription": "NTP connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533920",
      "port": "443",
      "protocol": "TCP",
      "source": "Mgmt clients",
      "destination": "Service IP Pool",
      "purpose": "HTTPS",
      "serviceDescription": "SSP inbound ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533921",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Installer",
      "destination": "VC",
      "purpose": "HTTPS",
      "serviceDescription": "SSP Installer to VC",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b2bc90690c64533922",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "VC",
      "purpose": "HTTPS",
      "serviceDescription": "CSI controller to vc",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533923",
      "port": "514",
      "protocol": "UDP",
      "source": "SSP Node IP Pool",
      "destination": "Syslog server",
      "purpose": "Syslog",
      "serviceDescription": "Syslog output (if configured)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533924",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "vCenter Server",
      "purpose": "HTTPS",
      "serviceDescription": "SSP outbound vc/nsx mgr",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533925",
      "port": "22",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SFTP backup server",
      "purpose": "SFTP",
      "serviceDescription": "Backup & Restore (if configured) Support Bundle (if configured)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533926",
      "port": "389 / 636 / 3268 / 3269",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "LDAP (server)",
      "purpose": "LDAP / LDAPS",
      "serviceDescription": "SSP outbound",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533927",
      "port": "2379",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "kube-apiserver -> etcd",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533928",
      "port": "2380",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "etcd cluster",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533929",
      "port": "10250",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "API Server -> kubelet",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c6453392a",
      "port": "10256-10257",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "kube-controller-manager health check",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c6453392b",
      "port": "10259",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "kube-proxy health check",
      "serviceDescription": "SSP controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c6453392c",
      "port": "8091",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "Antrea Health check",
      "serviceDescription": "SSP Antrea controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c6453392d",
      "port": "10349-10351",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "Antrea API server & metrics",
      "serviceDescription": "SSP Antrea controller",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c6453392e",
      "port": "6081",
      "protocol": "UDP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "Geneve tunnel",
      "serviceDescription": "Antrea tunnel (geneve)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c6453392f",
      "port": "2112",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "Kube-vip health check",
      "serviceDescription": "SSP controller kube-vip",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533930",
      "port": "7946",
      "protocol": "TCP/UDP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "Metallb speaker quorum",
      "serviceDescription": "SSP metallb",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533931",
      "port": "9808",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SSP Node IP Pool",
      "purpose": "CSI Health",
      "serviceDescription": "vmware csi",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533932",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "SIEM server",
      "purpose": "Required for NDR when configured to send events to SIEM",
      "serviceDescription": "SIEM events (if configured)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b3bc90690c64533933",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "*.prod.nsxti.vmware.com",
      "purpose": "Required for NDR if not running in airgap mode",
      "serviceDescription": "VTIS",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c64533934",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "nsx.lastline.com",
      "purpose": "Required for NDR if not running in airgap mode",
      "serviceDescription": "vDefend Advanced Threat Prevention Cloud",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c64533935",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "nsx.west.us.lastline.com nsx.nl.emea.lastline.com",
      "purpose": "Required for NDR and MPS if not running in airgap mode",
      "serviceDescription": "vDefend Advanced Threat Prevention Cloud",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c64533936",
      "port": "3260 (iSCSI) 2049 (NFS)",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "ESXi server hosting the shared storage",
      "purpose": "Shared Storage",
      "serviceDescription": "Worker node to vsphere datastore",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c64533937",
      "port": "9092",
      "protocol": "TCP",
      "source": "ESXi hosts (NSX TNs)",
      "destination": "SSP Service IP Pool",
      "purpose": "Flow / IDPS data from TN",
      "serviceDescription": "SSP inbound kafka",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c64533938",
      "port": "443",
      "protocol": "TCP",
      "source": "ESXi hosts & Edge Nodes (NSX TNs)",
      "destination": "SSP Service IP Pool 1st IP",
      "purpose": "Metrics",
      "serviceDescription": "SSP inbound Ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c64533939",
      "port": "9092",
      "protocol": "TCP",
      "source": "NSX Mgr",
      "destination": "SSP Service IP Pool",
      "purpose": "config sync",
      "serviceDescription": "SSP inbound kafka",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c6453393a",
      "port": "443",
      "protocol": "TCP",
      "source": "NSX Mgr",
      "destination": "SSP Service IP Pool 1st IP address",
      "purpose": "Metrics",
      "serviceDescription": "SSP inbound Ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c6453393b",
      "port": "9092",
      "protocol": "TCP",
      "source": "SVM",
      "destination": "SSP Service IP Pool",
      "purpose": "Kafka for MPS events",
      "serviceDescription": "SSP inbound kafka",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c6453393c",
      "port": "443",
      "protocol": "TCP",
      "source": "SVM",
      "destination": "SSP Service IP Pool",
      "purpose": "Metrics",
      "serviceDescription": "SSP inbound ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c6453393d",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "SVM",
      "destination": "DNS server",
      "purpose": "DNS",
      "serviceDescription": "DNS connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8ea5b4bc90690c6453393e",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "NSX Manager",
      "purpose": "HTTPS",
      "serviceDescription": "SSP outbound NSX connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d87128e5d2932fc84b97",
          "name": "5.1"
        },
        {
          "id": "6a87dac1b4c83d53e3ed5521",
          "name": "5.0"
        },
        {
          "id": "6a87d885b4c83d53e3ed5520",
          "name": "5.1.1"
        }
      ]
    },
    {
      "id": "6a8eeb6b0e97f0c02840f15e",
      "port": "443",
      "protocol": "TCP",
      "source": "Mgmt clients",
      "destination": "Service IP Pool first IP",
      "purpose": "HTTPS",
      "serviceDescription": "SSP inbound ingress",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6b0e97f0c02840f15f",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "*.prod.nsxti.vmware.com",
      "purpose": "Required for AI Assistant, NDR and MPS if not running in airgap mode",
      "serviceDescription": "VTIS",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6b0e97f0c02840f160",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "*.aiplatform.googleapis.com",
      "purpose": "Required for AI Assistant",
      "serviceDescription": "AI Assistant",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f161",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "apiplatform.*.rep.googleapis.com",
      "purpose": "Required for AI Assistant",
      "serviceDescription": "AI Assistant",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f162",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "*.services.ai.azure.com",
      "purpose": "Required for AI Assistant for threat defense",
      "serviceDescription": "AI Assistant for threat defense",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f163",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "vdefend-intelligent-assist.broadcom.com",
      "purpose": "Required for AI Assistant",
      "serviceDescription": "AI Assistant",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f164",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "nsx.lastline.com",
      "purpose": "Required for NDR and MPS if not running in airgap mode",
      "serviceDescription": "NSX ATP Cloud Services",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f165",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "nsx.west.us.lastline.com nsx.nl.emea.lastline.com",
      "purpose": "Required for NDR and MPS if not running in airgap mode",
      "serviceDescription": "NSX ATP Cloud Services (regional endpoint as appropriate based on selected region)",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f166",
      "port": "1194",
      "protocol": "UDP",
      "source": "SSP Node IP Pool",
      "destination": "udp.anonvpn.broadcom.com",
      "purpose": "openvpn connection to ATP Cloud  for sandbox traffic",
      "serviceDescription": "SSP inbound and outbound to vDefend ATP Cloud services",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f167",
      "port": "1194",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "tcp.anonvpn.broadcom.com",
      "purpose": "openvpn connection to ATP Cloud for sandbox traffic",
      "serviceDescription": "SSP inbound and outbound to vDefend ATP Cloud services",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f168",
      "port": "443",
      "protocol": "HTTPS",
      "source": "SSP Node IP Pool",
      "destination": "management.lastline.com",
      "purpose": "openvpn connection via HTTPS tunnel to ATP Cloud for sandbox traffic",
      "serviceDescription": "vDefend ATP Cloud services",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f169",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "Sandbox vCenter",
      "purpose": "HTTPS",
      "serviceDescription": "MPS services to Sandbox vCenter",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f16a",
      "port": "443",
      "protocol": "TCP",
      "source": "SSP Node IP Pool",
      "destination": "Sandbox ESX hosts",
      "purpose": "HTTPS",
      "serviceDescription": "MPS services to Sandbox ESX hosts",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f16b",
      "port": "1194",
      "protocol": "UDP",
      "source": "MPS VPN Gateway VM",
      "destination": "SSP Node IP Pool",
      "purpose": "Sandbox traffic over VPN tunnel",
      "serviceDescription": "OpenVPN Tunnel",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f16c",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "MPS VPN Gateway VM",
      "destination": "NTP servers",
      "purpose": "DNS",
      "serviceDescription": "DNS connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a8eeb6c0e97f0c02840f16d",
      "port": "123",
      "protocol": "UDP",
      "source": "MPS VPN Gateway VM",
      "destination": "NTP servers",
      "purpose": "NTP",
      "serviceDescription": "NTP connection",
      "classification": "N/A",
      "publishDate": "2026-08-23T00:00:00Z",
      "product": "VMware vDefend",
      "productId": "6a05a29e4020a053ebfe0770",
      "releases": [
        {
          "id": "6a87d89e28e5d2932fc84b98",
          "name": "5.2"
        }
      ]
    },
    {
      "id": "6a19566bc2b516e599a35ec9",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Avi Controller",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into the Avi Controller.",
      "classification": "Inbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566bc2b516e599a35eca",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Avi Controller",
      "purpose": "HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS for the Avi Controller UI.",
      "classification": "Inbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ecb",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Avi Controller",
      "purpose": "Avi Controller UI / API",
      "serviceDescription": "Primary HTTPS port for the Avi Controller UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ecc",
      "port": "5054",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "Avi Controller",
      "purpose": "Avi Controller CLI shell",
      "serviceDescription": "Optional: remote CLI shell access to the Avi Controller.",
      "classification": "Inbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ecd",
      "port": "161",
      "protocol": "UDP",
      "source": "Management Workstations",
      "destination": "Avi Controller",
      "purpose": "SNMP query",
      "serviceDescription": "Optional: SNMP query of the Avi Controller.",
      "classification": "Inbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ece",
      "port": "443",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "ESX Management IP addresses",
      "purpose": "Service Engine image transfer",
      "serviceDescription": "Avi Controller pushes Service Engine images to ESX hosts during deployment when not using Content Library.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ecf",
      "port": "443",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "vCenter Server Management IP address",
      "purpose": "vCenter integration",
      "serviceDescription": "Avi Controller integration with vCenter Server.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ed0",
      "port": "443",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "NSX Manager",
      "purpose": "NSX integration",
      "serviceDescription": "Avi Controller integration with NSX Manager.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ed1",
      "port": "53",
      "protocol": "UDP",
      "source": "Avi Controller",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ed2",
      "port": "123",
      "protocol": "UDP",
      "source": "Avi Controller",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ed3",
      "port": "514",
      "protocol": "UDP",
      "source": "Avi Controller",
      "destination": "Syslog Servers",
      "purpose": "Syslog",
      "serviceDescription": "Syslog forwarding from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566cc2b516e599a35ed4",
      "port": "25",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Email Server",
      "purpose": "SMTP",
      "serviceDescription": "Avi Controller SMTP for email notifications.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35ed5",
      "port": "162",
      "protocol": "UDP",
      "source": "Avi Controller",
      "destination": "SNMP Management System",
      "purpose": "SNMP traps",
      "serviceDescription": "Optional: SNMP trap output from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35ed6",
      "port": "389",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "LDAP authentication from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35ed7",
      "port": "389",
      "protocol": "UDP",
      "source": "Avi Controller",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "LDAP authentication from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35ed8",
      "port": "636",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "LDAPS authentication from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35ed9",
      "port": "49",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "TACACS+ Server",
      "purpose": "TACACS+",
      "serviceDescription": "TACACS+ authentication from the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35eda",
      "port": "443",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Cloud Provider APIs",
      "purpose": "Cloud provider integration",
      "serviceDescription": "Avi Controller integration with public-cloud (AWS, Azure, GCP) API endpoints.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35edb",
      "port": "22",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Avi Controller",
      "purpose": "Cluster SSH",
      "serviceDescription": "SSH between Avi Controller cluster nodes for secure channel operations.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35edc",
      "port": "443",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Avi Controller",
      "purpose": "Cluster API",
      "serviceDescription": "HTTPS between Avi Controller cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35edd",
      "port": "8443",
      "protocol": "TCP",
      "source": "Avi Controller",
      "destination": "Avi Controller",
      "purpose": "Secure channel key exchange",
      "serviceDescription": "Secure channel key exchange between Avi Controller cluster nodes.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566dc2b516e599a35ede",
      "port": "22",
      "protocol": "TCP",
      "source": "Avi Service Engine",
      "destination": "Avi Controller",
      "purpose": "SE secure channel (SSH)",
      "serviceDescription": "SSH between Avi Service Engines and the Avi Controller.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35edf",
      "port": "8443",
      "protocol": "TCP",
      "source": "Avi Service Engine",
      "destination": "Avi Controller",
      "purpose": "SE secure channel key exchange",
      "serviceDescription": "Secure channel key exchange between Avi Service Engines and the Avi Controller.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee0",
      "port": "123",
      "protocol": "UDP",
      "source": "Avi Service Engine",
      "destination": "Avi Controller",
      "purpose": "NTP from SE",
      "serviceDescription": "Avi Service Engine NTP synchronization via the Avi Controller.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee1",
      "port": "9001",
      "protocol": "TCP",
      "source": "Avi Service Engine",
      "destination": "Avi Service Engine",
      "purpose": "Inter-SE object store (vCenter/NSX/Linux)",
      "serviceDescription": "Inter-SE distributed object store for vCenter, NSX-T, no-orchestrator, and Linux-server clouds.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee2",
      "port": "4001",
      "protocol": "TCP",
      "source": "Avi Service Engine",
      "destination": "Avi Service Engine",
      "purpose": "Inter-SE object store (public cloud)",
      "serviceDescription": "Inter-SE distributed object store for AWS, Azure, and GCP. ObjectSync is disabled by default in 30.2.x; enabled in 31.1.x for new deployments only.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee3",
      "port": "Any",
      "protocol": "TCP/UDP",
      "source": "Application Clients",
      "destination": "Avi VIP (Service Engine Data interface)",
      "purpose": "Client traffic to VIP",
      "serviceDescription": "Virtual service front-end traffic from clients to the VIP. Port and protocol depend on the configured virtual service.",
      "classification": "Inbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee4",
      "port": "Any",
      "protocol": "TCP/UDP",
      "source": "Avi Service Engine",
      "destination": "Pool Application Servers",
      "purpose": "Backend pool traffic",
      "serviceDescription": "Load-balanced traffic from the Service Engine data interface to backend pool members. Port depends on pool configuration.",
      "classification": "Outbound",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee5",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "Avi Controller",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Avi Controller and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee6",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "Avi Controller",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Avi Controller and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee7",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "Avi Controller",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Avi Controller and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a19566ec2b516e599a35ee8",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "Avi Controller",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping, traceroute, and Path MTU Discovery between the Avi Controller and admin workstations.",
      "classification": "Both",
      "publishDate": "2026-05-26T00:00:00Z",
      "product": "Avi Load Balancer",
      "productId": "6a05a3864020a053ebfe0771",
      "releases": [
        {
          "id": "6a05a3d69044725e5fb7c252",
          "name": "32.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c255",
      "port": "5480",
      "protocol": "HTTPS",
      "source": "Web Browser",
      "destination": "Protection and Recovery Appliance",
      "purpose": "Protection and Recovery Appliance Management interface",
      "serviceDescription": "VRMS Appliance Management Interface. Also required for UI Health status and when the vCenter is configured in \"Enhanced Linked Mode\"",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c256",
      "port": "32032",
      "protocol": "TLS",
      "source": "ESXi host on the source site",
      "destination": "vSphere Replication server on the target site",
      "purpose": "Replication traffic for Legacy vSphere Replication",
      "serviceDescription": "Initial and outgoing replication traffic from the ESXi host on the source site to the vSphere Replication or vSphere Replication server on the target site for replication traffic with network encryption",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c257",
      "port": "32032",
      "protocol": "TCP",
      "source": "ESXi host on the source site",
      "destination": "ESX host of the target site",
      "purpose": "Replication traffic ports required for Enhanced vSphere Replication",
      "serviceDescription": "Initial and outgoing replication traffic from the source ESX hosts on which the replicated VMs are running to the target ESX hosts of the cluster containing the target datastore",
      "classification": "Both",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c258",
      "port": "31031",
      "protocol": "TCP",
      "source": "ESXi host on the source site",
      "destination": "vSphere Replication server on the target site",
      "purpose": "Replication traffic ports required for Legacy vSphere Replication",
      "serviceDescription": "Initial and outgoing replication traffic from the ESXi host on the source site to the vSphere Replication appliance or vSphere Replication server at the target site for replication traffic without network encryption.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c259",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Site Recovery UI client",
      "destination": "Local Protection and Recovery Appliance",
      "purpose": "vSphere Replication management",
      "serviceDescription": "Default port for the Site Recovery UI client when you open it from the vSphere Replication appliance.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c25a",
      "port": "443",
      "protocol": "TCP",
      "source": "Site Recovery UI client",
      "destination": "Remote Protection and Recovery Appliance",
      "purpose": "vSphere Replication management",
      "serviceDescription": "TCP port 443 must be open when you access the Site Recovery UI client from the vSphere Replication appliance",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c25b",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Site Recovery UI client",
      "destination": "Local and remote vCenter Server or all vCenter Server instances in Enhanced Linked Mode with a registered vSphere Replication",
      "purpose": "vSphere Replication management",
      "serviceDescription": "Default port for the Site Recovery UI client when you open it from the vSphere Replication appliance.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5039044725e5fb7c25c",
      "port": "902",
      "protocol": "TCP/UDP",
      "source": "vSphere Replication server on the target site",
      "destination": "ESXi host (intra-site only) on target site",
      "purpose": "vSphere Replication management infra-site traffic",
      "serviceDescription": "Traffic between the vSphere Replication server and the ESXi hosts on the same site. Specifically the traffic of the NFC service to the destination ESXi servers.",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5049044725e5fb7c25d",
      "port": "8123",
      "protocol": "HTTPS",
      "source": "Protection and Recovery Appliance",
      "destination": "vSphere Replication server",
      "purpose": "vSphere Replication management infra-site traffic",
      "serviceDescription": "Intra-site management traffic from the vSphere Replication Management server to additional vSphere Replication server in the environment for legacy vSphere Replication",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5049044725e5fb7c25e",
      "port": "443",
      "protocol": "TCP",
      "source": "Protection and Recovery Appliance",
      "destination": "https://vcsa.vmware.com",
      "purpose": "Sending diagnostic data",
      "serviceDescription": "Customer Experience Improvement Program (CEIP) for vSphere Replication.",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5049044725e5fb7c25f",
      "port": "443",
      "protocol": "TCP",
      "source": "Protection and Recovery Appliance",
      "destination": "Local and Remote vCenter Server",
      "purpose": "vSphere Replication management traffic",
      "serviceDescription": "All management traffic to the vSphere Replication appliance to local and remote vCenter",
      "classification": "Both",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5049044725e5fb7c260",
      "port": "443",
      "protocol": "HTTP",
      "source": "vSphere Replication in the Protection and Recovery Appliance",
      "destination": "Local ESXi host (intra-site)",
      "purpose": "vSphere Replication management infra-site traffic",
      "serviceDescription": "Traffic between vSphere Replication and the ESXi hosts on the same site",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5049044725e5fb7c261",
      "port": "9084",
      "protocol": "HTTP",
      "source": "Protection and Recovery Appliance",
      "destination": "Local vCenter Server",
      "purpose": "vSphere Replication management infra-site",
      "serviceDescription": "Used for uploading the hbr agent VIB to vCenter Server during the installation of the VIB file to the source ESXi hosts. Required only with ESX 9.0.x hosts or lower version",
      "classification": "Outbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5049044725e5fb7c262",
      "port": "5480",
      "protocol": "HTTPS",
      "source": "Local Protection and Recovery Appliance",
      "destination": "Remote vSphere Replication Appliance",
      "purpose": "vSphere Replication management",
      "serviceDescription": "Local vSphere Replication needs to check the health status of remote vSphere Replication via port 5480 if the vCenter servers are in ehnanced linked mode",
      "classification": "Inbound",
      "publishDate": "2026-08-31T00:00:00Z",
      "product": "vSphere Replication",
      "productId": "6a06b6a41809eae1a581f6ac",
      "releases": [
        {
          "id": "6a06b6bc9044725e5fb7c253",
          "name": "9.1"
        },
        {
          "id": "6a9524b30a0f8afb34ca2e85",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c7e99044725e5fb7c26d",
      "port": "32032",
      "protocol": "TCP",
      "source": "Protection and Recovery Proxy appliance ot the target site",
      "destination": "Connection Broker service in Protection and Recovery appliance on the target site",
      "purpose": "Broker traffic for Protection and recovery service for VCF Automation",
      "serviceDescription": "Broker traffic (in-band datapath) on the replication network",
      "classification": "Both",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery Service for VCF Automation",
      "productId": "6a06c43a1809eae1a581f6ad",
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c7ea9044725e5fb7c26e",
      "port": "8736",
      "protocol": "TCP",
      "source": "Local Protection and Recovery Proxy appliance",
      "destination": "Remote Protection and Recovery Proxy appliance",
      "purpose": "Replication traffic for Protection and recovery service for VCF Automation",
      "serviceDescription": "Inter-site replication traffic (data-path). Supposed to be configured on the NSX link between the sites",
      "classification": "Both",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery Service for VCF Automation",
      "productId": "6a06c43a1809eae1a581f6ad",
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c7ec9044725e5fb7c26f",
      "port": "433",
      "protocol": "HTTPS",
      "source": "Local Protection and Recovery Proxy appliance",
      "destination": "Local vSphere Replication Management service in Protection and Recovery appliance",
      "purpose": "Management traffic for Protection and recovery service for VCF Automation",
      "serviceDescription": "Incomming management traffic to the hbrproxy VAPI endpoint",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery Service for VCF Automation",
      "productId": "6a06c43a1809eae1a581f6ad",
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c7ee9044725e5fb7c270",
      "port": "68",
      "protocol": "UDP",
      "source": "DHCP Server",
      "destination": "Protection and Recovery Proxy appliance",
      "purpose": "Proxy Appliance port for Protection and recovery service for VCF Automation",
      "serviceDescription": "Used for DHCP client",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery Service for VCF Automation",
      "productId": "6a06c43a1809eae1a581f6ad",
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c7f09044725e5fb7c271",
      "port": "5353",
      "protocol": "UDP",
      "source": "mDNS service",
      "destination": "Protection and Recovery Proxy appliance",
      "purpose": "Proxy Appliance port for Protection and recovery service for VCF Automation",
      "serviceDescription": "Used for Multicast Domain Name System (mDNS)",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery Service for VCF Automation",
      "productId": "6a06c43a1809eae1a581f6ad",
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c7f29044725e5fb7c272",
      "port": "22",
      "protocol": "TCP",
      "source": "SSH service",
      "destination": "Protection and Recovery Proxy appliance",
      "purpose": "Proxy Appliance port for Protection and recovery service for VCF Automation",
      "serviceDescription": "Used if SSH is enabled ",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery Service for VCF Automation",
      "productId": "6a06c43a1809eae1a581f6ad",
      "releases": [
        {
          "id": "6a06c44e9044725e5fb7c254",
          "name": "9.1.0"
        },
        {
          "id": "6aa2516e4a973bfa11ce1656",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf19044725e5fb7c273",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Site Recovery UI client",
      "destination": "Protection and Recovery",
      "purpose": "Management traffic to Protection and Recovery",
      "serviceDescription": "Default port for the Protection and Recovery",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf19044725e5fb7c274",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Site Recovery UI client",
      "destination": "Protection and Recovery Appliance",
      "purpose": "Management traffic to Protection and Recovery and VSAN Replications",
      "serviceDescription": "Management traffic to Protection and Recovery and vSAN Replication services",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf19044725e5fb7c275",
      "port": "443",
      "protocol": "HTTPS",
      "source": "vSphere Web Client",
      "destination": "Protection and Recovery",
      "purpose": "Management traffic to Protection and Recovery",
      "serviceDescription": "All management traffic to  Protection and Recovery Appliance goes to this port. This includes traffic by external API clients for task automation and HTTPS interface for downloading the UI plug-in and icons. This port must be accessible from the vCenter Server proxy system. Used by vSphere Web Client to download the Site Recovery client plug-in.",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c276",
      "port": "443",
      "protocol": "TCP",
      "source": "Protection and Recovery Appliance",
      "destination": "https://vcsa.vmware.com",
      "purpose": "Sending diagnostic data",
      "serviceDescription": "Customer Experience Improvement Program (CEIP) for Protection and Recovery",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c277",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Site Recovery UI client",
      "destination": "Local and remote vCenter Servers",
      "purpose": "Management traffic toProtection and Recovery",
      "serviceDescription": "Local and remote vCenter Server or all vCenter Server instances in Enhanced Linked Mode on which there is a registeredProtection and Recovery",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c278",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Protection and Recovery",
      "destination": "Local and Remote vCenter Server",
      "purpose": "Management traffic to Protection and Recovery",
      "serviceDescription": "Default SSL Web Port for incoming TCP traffic",
      "classification": "Both",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c279",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Protection and Recovery on the local site",
      "destination": "Protection and Recovery on remote site",
      "purpose": "Management traffic to Protection and Recovery",
      "serviceDescription": "Bidirectional communication betweenProtection and Recovery servers on local and remote sites",
      "classification": "Both",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c27a",
      "port": "5480",
      "protocol": "HTTPS",
      "source": "Web Browser",
      "destination": "Protection and Recovery Appliance",
      "purpose": "Protection and  Recovery Appliance Management interface",
      "serviceDescription": "Protection and Recovery Appliance Management Interface",
      "classification": "Inbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c27b",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Protection and Recovery",
      "destination": "VMware Live Recovery Cloud Console",
      "purpose": "Sending data to VLR cloud service",
      "serviceDescription": "Protection and Recovery communication to VLR cloud service endpoint",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c27c",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Protection and Recovery",
      "destination": "VMware Cloud Services Platform (CSP)",
      "purpose": "Sending data to VMware Cloud Services Platform (CSP)",
      "serviceDescription": "Protection and Recovery communication to VMware Cloud Services Platform (CSP)",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c27d",
      "port": "902",
      "protocol": "TCP/UDP",
      "source": "Protection and Recovery on the recovery site",
      "destination": "Recovery site ESXi host",
      "purpose": "Internal services",
      "serviceDescription": "Traffic from the  Protection and Recovery Server on the recovery site to ESXi hosts when recovering or testing virtual machines with IP customization, with configured callout commands on recovered virtual machines, or that use raw disk mapping (RDM). All NFC traffic for updating or patching the VMX files of virtual machines that are replicated using vSphere Replication use this port.",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf29044725e5fb7c27e",
      "port": "443",
      "protocol": "HTTPS",
      "source": "Protection and Recovery on the recovery site",
      "destination": "Recovery site ESXi host",
      "purpose": "Internal service",
      "serviceDescription": "Traffic from the Protection and Recovery Server on the recovery site to ESXi hosts when recovering or testing virtual machines with configured IP customization, or callout commands on recovered virtual machines.",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf39044725e5fb7c27f",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "SaaS Orchestrator",
      "purpose": "Sending data",
      "serviceDescription": "Management service",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf39044725e5fb7c280",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "Protection and Recovery on the source site",
      "purpose": "Internal services",
      "serviceDescription": "Management service",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf39044725e5fb7c281",
      "port": "80",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "vCenter Server",
      "purpose": "Internal services",
      "serviceDescription": "vCenter web service",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf39044725e5fb7c282",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "vCenter Server",
      "purpose": "External services",
      "serviceDescription": "vCenter Server Web Service",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06cbf39044725e5fb7c283",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "Broadcom support service ",
      "purpose": "Sending diagnostic data to support",
      "serviceDescription": "Support service",
      "classification": "Outbound",
      "publishDate": "2026-09-07T00:00:00Z",
      "product": "Protection and Recovery",
      "productId": "6a06c6584e349d6d9c172452",
      "releases": [
        {
          "id": "6a06c67b9044725e5fb7c264",
          "name": "9.1.0"
        },
        {
          "id": "6a97bf478a02c088cd7922bf",
          "name": "9.1.1"
        }
      ]
    },
    {
      "id": "6a06c5e5c2b516e599a35d5a",
      "port": "1492",
      "protocol": "TCP",
      "source": "ESXi",
      "destination": "Cyber Recovery Connector",
      "purpose": "VLCR replication traffic",
      "serviceDescription": "This port is used by vltd (transport) to replicate data to the VLCR cyber recovery connector using LWD.",
      "classification": "Inbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e5c2b516e599a35d5b",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "Cyber Recovery Connector",
      "destination": "DNS server",
      "purpose": "DNS service",
      "serviceDescription": "DNS server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e5c2b516e599a35d5c",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "Scale-out Cloud File System",
      "purpose": "Encrypted tunnel for data transfers and metadata operations",
      "serviceDescription": "Scale-out Cloud File System",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e6c2b516e599a35d5d",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "SaaS Orchestrator",
      "purpose": "Management service",
      "serviceDescription": "SaaS Orchestrator",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e6c2b516e599a35d5e",
      "port": "80",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector (on-premises deployments only)",
      "destination": "vCenter Server",
      "purpose": "vCenter web service",
      "serviceDescription": "vCenter Server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e6c2b516e599a35d5f",
      "port": "902",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector (needed for on-premises deployments only)",
      "destination": "ESXi Management IP addresses",
      "purpose": "Reading/writing vdisks",
      "serviceDescription": "ESXi Management IP addresses",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e6c2b516e599a35d60",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "vCenter Server",
      "purpose": "vCenter Server Web Service",
      "serviceDescription": "vCenter Server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c5e6c2b516e599a35d61",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "VMware Auto-support server",
      "purpose": "Support service",
      "serviceDescription": "VMware Auto-support server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71d9044725e5fb7c265",
      "port": "1492",
      "protocol": "TCP",
      "source": "ESXi",
      "destination": "Cyber Recovery Connector",
      "purpose": "VLCR replication traffic",
      "serviceDescription": "This port is used by vltd (transport) to replicate data to the VLCR cyber recovery connector using LWD.",
      "classification": "Inbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71d9044725e5fb7c266",
      "port": "53",
      "protocol": "TCP/UDP",
      "source": "Cyber Recovery Connector",
      "destination": "DNS server",
      "purpose": "DNS service",
      "serviceDescription": "DNS server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71d9044725e5fb7c267",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "Scale-out Cloud File System",
      "purpose": "Encrypted tunnel for data transfers and metadata operations",
      "serviceDescription": "Scale-out Cloud File System",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71e9044725e5fb7c268",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "SaaS Orchestrator",
      "purpose": "Management service",
      "serviceDescription": "SaaS Orchestrator",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71e9044725e5fb7c269",
      "port": "80",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector (on-premises deployments only)",
      "destination": "vCenter Server",
      "purpose": "vCenter web service",
      "serviceDescription": "vCenter Server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71e9044725e5fb7c26a",
      "port": "902",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector (needed for on-premises deployments only)",
      "destination": "ESXi Management IP addresses",
      "purpose": "Reading/writing vdisks",
      "serviceDescription": "ESXi Management IP addresses",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71e9044725e5fb7c26b",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "vCenter Server",
      "purpose": "vCenter Server Web Service",
      "serviceDescription": "vCenter Server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a06c71e9044725e5fb7c26c",
      "port": "443",
      "protocol": "TCP",
      "source": "Cyber Recovery Connector",
      "destination": "VMware Auto-support server",
      "purpose": "Support service",
      "serviceDescription": "VMware Auto-support server",
      "classification": "Outbound",
      "publishDate": "2026-05-12T00:00:00Z",
      "product": "VMware Live Recovery cloud",
      "productId": "6a06c5a81809eae1a581f6af",
      "releases": [
        {
          "id": "6a06c5c39044725e5fb7c263",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5253",
      "port": "30006",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Webhook API",
      "serviceDescription": "Webhooks called by Fleet Manager to trigger Day-2 operations on the Platform runtime.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5254",
      "port": "30005",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Health Check API",
      "serviceDescription": "Validates the Platform runtime is healthy prior to invoking lifecycle changes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5255",
      "port": "30001",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry (bootstrap)",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry at bootstrap.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5256",
      "port": "30000",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane OCI Registry",
      "serviceDescription": "Container images and Helm charts pushed to the OCI registry on the Platform control plane nodes.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5257",
      "port": "6443",
      "protocol": "TCP",
      "source": "VCF Operations Fleet Manager Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "Control Plane Management API",
      "serviceDescription": "Fleet Manager control plane management API requests to the Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5258",
      "port": "443",
      "protocol": "TCP",
      "source": "vCenter Server Management IP address",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "vCenter API to VMSP",
      "serviceDescription": "vCenter Server connects to the VCF Management Services Platform over HTTPS.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5259",
      "port": "5480",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP VAMI",
      "serviceDescription": "VAMI break-glass interface on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed525a",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP UI / API",
      "serviceDescription": "Primary HTTPS port on the VCF Management Services Platform for the UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed525b",
      "port": "80",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP HTTP (redirect)",
      "serviceDescription": "HTTP redirect to HTTPS on the VCF Management Services Platform.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed525c",
      "port": "ICMP Type 11/Code 0",
      "protocol": "ICMP",
      "source": "VCF Identity Broker",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Identity Broker and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed525d",
      "port": "ICMP Type 3/Code 4",
      "protocol": "ICMP",
      "source": "VCF Identity Broker",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Identity Broker and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed525e",
      "port": "ICMP Type 8/Code 0",
      "protocol": "ICMP",
      "source": "VCF Identity Broker",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Identity Broker and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed525f",
      "port": "ICMP Type 0/Code 0",
      "protocol": "ICMP",
      "source": "VCF Identity Broker",
      "destination": "Management Workstations",
      "purpose": "ICMP utility",
      "serviceDescription": "Ping (Echo / Echo Reply), traceroute (Time Exceeded), and Path MTU Discovery between VCF Identity Broker and Management Workstations.",
      "classification": "Both",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5260",
      "port": "123",
      "protocol": "UDP",
      "source": "VCF Identity Broker",
      "destination": "NTP Server",
      "purpose": "NTP",
      "serviceDescription": "Time synchronization for VCF Identity Broker.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5261",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Identity Broker",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Identity Broker.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5262",
      "port": "3269",
      "protocol": "TCP",
      "source": "VCF Identity Broker",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS Global Catalog (AD)",
      "serviceDescription": "VCF Identity Broker secure queries to the Active Directory Global Catalog.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5263",
      "port": "3268",
      "protocol": "TCP",
      "source": "VCF Identity Broker",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP Global Catalog (AD)",
      "serviceDescription": "VCF Identity Broker queries to the Active Directory Global Catalog.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af0fb4c83d53e3ed5264",
      "port": "636",
      "protocol": "TCP",
      "source": "VCF Identity Broker",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAPS (AD)",
      "serviceDescription": "VCF Identity Broker LDAPS queries to AD/LDAP. Port is configurable on the AD side.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed5265",
      "port": "389",
      "protocol": "TCP",
      "source": "VCF Identity Broker",
      "destination": "Microsoft Active Directory Domain Controllers",
      "purpose": "LDAP (AD)",
      "serviceDescription": "VCF Identity Broker LDAP queries to AD/LDAP when customer uses LDAP SSO. Port is configurable on the AD side.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed5266",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Identity Broker",
      "purpose": "VIDB UI / API",
      "serviceDescription": "HTTPS to the VCF Identity Broker Java application for UI and API access.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed5267",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Identity Broker",
      "purpose": "SSH (admin)",
      "serviceDescription": "Admin SSH into the VCF Identity Broker appliance.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed5268",
      "port": "443",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP UI / API",
      "serviceDescription": "Primary HTTPS port on the VCF Management Services Platform for the UI and REST API.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed5269",
      "port": "22",
      "protocol": "TCP",
      "source": "Management Workstations",
      "destination": "VCF Management Services Platform IP addresses",
      "purpose": "VMSP SSH (admin)",
      "serviceDescription": "Operator/admin SSH into the VCF Management Services Platform nodes underlying this product.",
      "classification": "Inbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed526a",
      "port": "53",
      "protocol": "UDP",
      "source": "VCF Identity Broker",
      "destination": "DNS Resolvers",
      "purpose": "DNS",
      "serviceDescription": "DNS client queries from VCF Identity Broker.",
      "classification": "Outbound",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed526b",
      "port": "2112",
      "protocol": "HTTP",
      "source": "Inter-nodes",
      "destination": "Kube-VIP Prometheus metrics",
      "purpose": "Kube-VIP Prometheus metrics",
      "serviceDescription": "Kube-VIP Prometheus metrics",
      "classification": "N/A",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    },
    {
      "id": "6a58af10b4c83d53e3ed526c",
      "port": "5480",
      "protocol": "HTTPS",
      "source": "User / Client",
      "destination": "VAMI interface",
      "purpose": "Mgmt port for troubleshooting",
      "serviceDescription": "VAMI interface",
      "classification": "N/A",
      "publishDate": "2026-07-13T00:00:00Z",
      "product": "Identity Broker",
      "productId": "698e2e44906bdda1d154fa6a",
      "releases": [
        {
          "id": "6a58aea3b4c83d53e3ed5252",
          "name": "9.1.0"
        }
      ]
    }
  ]
}
