Following are the ports need to open in firewall.
8443 TCP vCenter Server Linked Mode
10111 TCP vCenter Server vCenter Inventory Service Linked Mode Communication
636 TCP vCenter Server Linked Mode, this is the SSL port of the local instance.
902 TCP vCenter Server ESXi 6.x vCenter Server system uses to send data to managed hosts. This port must not be blocked by firewalls between the server and the hosts or between hosts.
902 TCP/UDP vSphere Client ESXi 6.x vSphere Client uses this ports to display virtual machine consoles.
7500 UDP vCenter Server vCenter Server Linked Mode, Java Discovery Port
135 TCP vCenter Server vCenter Server Linked Mode
389 TCP/UDP vCenter Server Linked vCenter Servers .This is the LDAP port number for the Directory Services for the vCenter Server group.
The vCenter Server system needs to bind to port 389, even if you are not joining this vCenter Server instance to a Linked Mode group. If another service is running on this port, you can run the LDAP service on any port from 1025 through 65535.
Please mark correct/helpful if your issue resolved.