<!-- Firewall configuration information -->
<ConfigRoot>

  <!-- Known and blessed servives -->

  <service id='0000'>
    <id>sshServer</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>22</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id='0001'>
    <id>sshClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>22</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id='0002'>
    <id>nfsClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id='0004'>
    <id>dhcp</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>68</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>src</porttype>
      <port>68</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0005'>
    <id>dns</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>53</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>53</port>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>53</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0006'>
    <id>snmp</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>161</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0007'>
    <id>ntpClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>123</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>    

  <!-- First-party optional services -->

  <service id='0008'>
    <id>CIMHttpServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>5988</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0009'>
    <id>CIMHttpsServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>5989</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0010'>
    <id>CIMSLP</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>427</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>src</porttype>
      <port>427</port>
    </rule>
    <rule id='0002'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>427</port>
    </rule>
    <rule id='0003'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>src</porttype>
      <port>427</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0011'>
    <id>iSCSI</id>
    <rule>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>3260</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id='0012'>
    <id>vpxHeartbeats</id>
    <rule>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>902</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0013'>
    <id>updateManager</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>80</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>9000</begin>
        <end>9100</end>
      </port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id='0014'>
    <id>faultTolerance</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>80</port>
    </rule>    
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>8100</port>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>8100</port>
    </rule>
    <rule id='0003'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>8200</port>
    </rule>
    <rule id='0004'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>8200</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0015'>
    <id>webAccess</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>80</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0016'>
    <id>vMotion</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>8000</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>8000</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0017'>
    <id>vSphereClient</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>902</port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>443</port>
    </rule>
    <enabled>true</enabled>
    <required>true</required>
  </service>

  <service id='0018'>
     <id>activeDirectoryAll</id>

     <!--
         the required ports are listed here:
         http://www.likewise.com/resources/documentation_library/manuals/open/likewise-open-guide.html#OpenOutboundPorts
     -->

     <!-- Kerberos 5 -->
     <rule id='0000'>
        <direction>outbound</direction>
        <protocol>udp</protocol>
        <porttype>dst</porttype>
        <port>88</port>
     </rule>
     <rule id='0001'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>88</port>
     </rule>

     <!-- NTP -->
     <rule id='0002'>
        <direction>outbound</direction>
        <protocol>udp</protocol>
        <porttype>dst</porttype>
        <port>123</port>
     </rule>

     <!-- NetBIOS Name Service -->
     <rule id='0003'>
        <direction>outbound</direction>
        <protocol>udp</protocol>
        <porttype>dst</porttype>
        <port>137</port>
     </rule>

     <!-- NetBIOS Session (SMB) -->
     <rule id='0004'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>139</port>
     </rule>

     <!-- LDAP -->
     <rule id='0005'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>389</port>
     </rule>
     <rule id='0006'>
        <direction>outbound</direction>
        <protocol>udp</protocol>
        <porttype>dst</porttype>
        <port>389</port>
     </rule>

     <!-- SMB over TCP -->
     <rule id='0007'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>445</port>
     </rule>

     <!-- Machine password changes -->
     <rule id='0008'>
        <direction>outbound</direction>
        <protocol>udp</protocol>
        <porttype>dst</porttype>
        <port>464</port>
     </rule>
     <rule id='0009'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>464</port>
     </rule>

     <!-- Global Catalog search -->
     <rule id='0010'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>3268</port>
     </rule>

     <!-- CAM service -->
     <rule id='0011'>
        <direction>outbound</direction>
        <protocol>tcp</protocol>
        <porttype>dst</porttype>
        <port>51915</port>
     </rule>
 
     <enabled>false</enabled>
     <required>false</required>

  </service>

  <service id='0019'>
    <id>NFC</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>902</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>902</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <service id='0020'>
    <id>HBR</id>
    <!-- vSphere Replication traffic initiated from VMkernel on 
    port 31031 (initial sync), and port 44046 (on-going replication).  
    See PR 610578. -->
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>31031</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>44046</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <!-- Just for active mode ftp access -->
  <service id='0021'>
    <id>ftpClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>21</port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>src</porttype>
      <port>20</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0022">
    <id>httpClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>80</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>443</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id='0023'>
    <id>gdbserver</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>1000</begin>
        <end>9999</end>
      </port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>50000</begin>
        <end>50999</end>
      </port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0024">
    <id>DVFilter</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>2222</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0025">
    <id>DHCPv6</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>547</port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>546</port>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>547</port>
    </rule>
    <rule id='0003'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>546</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0026">
    <id>DVSSync</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>8302</port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>8301</port>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>8301</port>
    </rule>
    <rule id='0003'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>8302</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0027">
    <id>syslog</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>514</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>514</port>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>1514</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0028">
    <id>IKED</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>500</port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>500</port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <service id="0029">
    <id>WOL</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>9</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>

  <!-- Remote serial port with vSPC: all remote serial port traffic is initiated by us -->
  <service id="0030">
    <id>vSPC</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <!-- Remote serial port without vSPC: we may be listening -->
  <service id="0031">
    <id>remoteSerialPort</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>23</port>
    </rule>
    <rule id='0002'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <porttype>dst</porttype>
      <port>
        <begin>1024</begin>
        <end>65535</end>
      </port>
    </rule>
    <enabled>false</enabled>
    <required>false</required>
  </service>

  <!-- netDump -->
  <service id="0032">
    <id>netDump</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <porttype>dst</porttype>
      <port>6500</port>
    </rule>
    <enabled>true</enabled>
    <required>false</required>
  </service>
  
<!-- E-MAIL SMTP -->                 
  <service id='1000'>                                          
    <id>SMTP</id>                                                    
    <rule>                      
      <direction>outbound</direction>
      <protocol>tcp</protocol>                 
      <porttype>dst</porttype>                 
      <port>25</port>                               
    </rule>                                         
    <enabled>true</enabled>                         
    <required>false</required>                                   
  </service> 
</ConfigRoot>
