Limit a group only port to be added to virtual machines with the role


We have two 5.1 (soon to 5.5) Vmware ESXi clusters to total 10 hosts. We are setting up the new virtual machines for the Department of finance where they want to ensure that a level 1 technical support cannot access. On the side of the virtual machine, it's easy enough - but we want to make them a regular technician can also put a virtual machine on the portgroup (and VLAN) that these machines will be also on.

Is there a way to limit a single portgroup to be assigned to any virtual computer through roles?

Thanks in advance!


His quiet easily. Go to vCenter.--> Home---> Networking.

Select the Portgroup where you want to restrict users. Go to tab permissions, do a right click and add permissions.

Add all users and groups that should not have access to this and give as no access. They would never know that there

Tags: VMware

Similar Questions

  • Put virtual machines inside the VMkernel port group


    Network for administrators of VMware SIAS layout:

    "You can not put VMs within that group of port because it is made especially for a VMkernel port."

    However, I use ESXi 5.5 and is able to put normal interface of VM inside the vmk port group. (I only created 1 vmk port group so all virtual machines in the same group with the vmkernel interface)

    May I know if this is a new feature, or something is wrong?

    Thank you!

    This may be possible with distributed switches not with standard switches.

  • I have an imac 27 "... on power there is no signal to startap, usb ports are not working and its deadlock with the logo of the Apple with the circle of rotation... Help, please

    I have an imac 27 "... on power there is no signal to startap, usb ports are not working and its deadlock with the logo of the Apple with the circle of rotation... Help, please

    Wake the computer to your Apple store or Apple authorized service for the service provider. He probably suffered a hardware failure.

  • Which side is the usb port 3 on a 2015 macbook pro with the retina display?

    Which side is the usb port 3 on a 2015 macbook pro with the retina display?

    I found the answer. It's the left side near the microphone.

  • Will the virtual machines in the space are automatically deleted when the protected group are removed

    Hi friends,

    Will the virtual machines in the space are automatically deleted when the protected group are removed?

    Thank you.


    When you choose to delete the Protection Group, first virtual machines are unprotected and placeholders are deleted.


  • Backup Virtual Machines on the (external) drive using only vSphere4 customer?


    I'm trying to make a backup of my virtual drive installed on an external hard drive (eSATA). The disc is recognized and everything seems fine, but I can't find a feature in vSphere4 client that allows me to copy a virtual machine. In "Datastore Browser", there is a function that allows to move the virtual machine to a data store to another, but not copy.

    The only option that I've found so far is to copy the virtual machine for the labtop vSphere4 a client by using the "Download" feature but it is very very slow due to 100MBit/s network and HARD drive connected by USB.

    I missed something in the vSphere4 customer?

    I am aware that VMware Data Recovery does just that, but I don't have the money to buy the necessary license.

    Kind regards


    One option is to enter the folder, select all the files, right click and select copy, and then create a new folder, enter into it, right click and select Paste.


  • Adding pages that integrate with the previous and sebsequent.

    Now if I add a page and delete text on the page before the addition of the page, text on the page after adding the page moves back to the previous page as if the new page wasn't there?  How can I get InDesign to recognize the addition of the page in the document, this text is screwed to the addition of the page?

    And is there an easy way to block all text and graphics on a specific page, for example, the title page chapter so it isn't thread returns to the previous page, when something is deleted on the previous page?

    InDesign is not a word processor. If you want a string of blocks of text, you need to add a block of text to the new page, click the out port of the block of text on the previous page and then click in the text frame on the new page. The out port can be seen here (circled in red):

    Jim-Montreal wrote:

    And is there an easy way to block all text and graphics on a specific page, for example, the title page chapter so it isn't thread returns to the previous page, when something is deleted on the previous page?

    Do not include the things that you do not want to flow with the text in the text flow. Use a block of text. In addition, you would benefit from an InDesign training. This book was recommended by many on this forum: CC InDesign: Visual QuickStart Guide (version 2014): Sandee Cohen: 9780133953565: books

  • define an id scsi for a disc newly added for virtual machines via script

    Hi Experts,

    I used the script below to add disks to several virtual machines

    But currently our requirement for change as if we must add 3 2 GB drives, the disks must the controller use SCSI (1:0) - (1:2)

    And next bunch of disks, for example, should use use SCSI (2:0) - (2:2).

    Y at - it an option to set the SCSI ID when adding new disks.
    Please let me know if there is nothing we can achieve through scripts.

    Thanks in advance.

    Kind regards

    Try this new version, it works for me in my test environment

    ### Get VM/Disk Count/Datastore information ### $vmname = Read-Host "VM Name to add disks to"$num_disks = Read-Host "number of disks to add"$ds = "Oracle DB Farm Datastore Group"$format = Read-Host "Disk Format (thin, thick, EagerZeroedThick)"$size = Read-Host "Disk Size (GB)"
    $vm = Get-VM $vmname$datastore = Get-DatastoreCluster -Name $ds
    ### Add $num_disks to VM1..$num_disks | %{  Write-Host "Adding disk $_ size $size GB and format $format to $($vm.Name) on datastore $datastore"
      if($_ -eq 1){      $hd = New-HardDisk -vm $vm -CapacityGB $size -Datastore $datastore -StorageFormat $format      $hd = Get-HardDisk -VM $vm | Where {$_.ExtensionData.Backing.UUid -eq $hd.ExtensionData.Backing.Uuid}      $ctrl = New-ScsiController -Type Paravirtual -HardDisk $hd  }  else{      $hd = New-HardDisk -vm $vm -CapacityGB $size -Datastore $datastore -StorageFormat $format -Controller $ctrl    $hd = Get-HardDisk -VM $vm | Where {$_.ExtensionData.Backing.UUid -eq $hd.ExtensionData.Backing.Uuid}  }}
  • no connectivity between the virtual machines on the guest only network

    I have trouble getting the network connectivity between two Windows 7 computers using a guest only network virtual in VMware Player.  Each virtual machine is able to get a (unique) IP address via dhcp and can ping itself and the bridge, but could not reach the other system.  I looked on my host computer adapter VMnet1 in Wireshark and saw incoming icmp packets in, but nothing is returned new.  My vmnetdhcp.conf file is unchanged with the exception to add a line to set the default gateway on my guests.  It was an attempt to solve this problem, and the same behavior was observed before changing anything.  Here are the details for this network segment:

    subnet netmask {}
    range;            # by default allows up to 125 VM
    option broadcast-address;
    option domain-name-servers
    option domain-name "localdomain".
    routers option;  # This is the line, I added
    by default-lease-time 1800;
    Max-lease-time 7200;
    host VMnet1 {}
    Hardware ethernet 00:50:56:C0:00:01;
    option domain-name-servers
    option domain-name ";

    Is there a problem with my configuration somewhere, or is it just a limitation of VMware Player?

    You may need to allow ICMP traffic of WF with Windows 7 as OS.


  • How to add the AD security group in each virtual machine with a name corresponding in VCenter?

    Hi all

    I would like to know if it is possible with VMware PowerCLI v4.1, I created the universal security group called 'Local administrators on %ComputerName%' for each server I have in UO computers by location OR separate and that he manually add members of the Local, but I want to attribute this security group in each computer virtual with the same name if possible.

    Basically, it's something like this:

    In the ad, here are computer objects: mailserver1-VM DBServer1-VM ApplicationServer1-VM

    In the ad's local security group objects: 'Administrator locally on mailserver1-VM' 'Local on DBServer1-VM administrator. 'Local on ApplicationServer1-VM administrator.

    So I want to affect these security group in each respective name of VMS in VCenter:
    Mailserver1-VM - Local Administrator on mailserver1-VM - role: read-only
    DBServer1-VM - Local Administrator on DBServer1-VM - role: read-only
    ApplicationServer1-VM - Local Administrator on ApplicationServer1-VM - role: read-only

    Any kind of aid and assistance would be appreciated grgeatly.

    Thank you.

    Hi Albert,

    I don't know what you want to check exactly, so I give 2 possible solutions.

    (1) you have a fixed number of names known to virtual machines for which you want to add this permission.

    $targetVM = "MailServer1-VM","DBServer1-VM","ApplicationServer1-VM"
    Get-Cluster -Name HighPerformanceCluster1 | Get-VM | `    where {$targetVM -contains $_.Name} | %{    New-VIPermission -Entity $_ -Principal ("DOMAIN\Local Administrator on " + $_.Name) `       -Role (Get-VIRole -Name ReadOnly) -Confirm:$false   }

    (2) you want to check for each virtual computer if the security group exist and then add the authorization.

    Get-Cluster -Name HighPerformanceCluster1 | Get-VM | `    Where{Get-QADObject ("DOMAIN\Local Administrator on " + $_.Name) `        -DontUseDefaultIncludedProperties -WarningAction SilentlyContinue `        -ErrorAction SilentlyContinue -SizeLimit 1} | %{    New-VIPermission -Entity $_ -Principal ("DOMAIN\Local Administrator on " + $_.Name) `        -Role (Get-VIRole -Name ReadOnly) -Confirm:$false} 

    Note that this requires the Quest AD snap-in must be installed. If you have a version without the Quest AD snap let me know.

  • Adding a virtual machine that has been previously saved

    Hello. I backed up a virtual machine that was running in an ESX (ESX n ° 1) and transfer all of its files in an a different ESX (ESX No. 2) data store. How should I add this VM in the new ESX (ESX No. 2)? I'm not using vCenter, I connect directly to the ESX Server via vSphere Client.

    The only way I found to do this is to create a new virtual machine in ESX No. 2, and when I add the new hard drive, I select the old VM hard. But this process is not so clean. For example, I read that if I used vCenter I'd be able to disconnect the server ESX n ° 2 of my datacenter and plug it back again, and when I do he added all the virtual machines that are within its data store automatically. The problem, as I said, is that I'm not using vCenter.

    Thanks in advance.


    Once you access the data store and find the files, you can simply right click on the VMX file and select "Add to inventory."  This will allow you to add the virtual machine to your host without manually creating a new virtual machine and pointing to the existing VMDK file.

  • Uninstall only partially work. Gel - leaving me stuck with the parts of the products on my system.

    Yesterday, one of your members of staff to chat support (Shilpa - 11 juin 2016: 24: 15 this) insisted I download 'Adobe Application Manager' and with it Adobe Creative Cloud, which I had not seen on my computer before. Download which has achieved precisely nothing and seems to actually have made things worse.

    I'm still trying to uninstall CS6, but something is happening and freezing blocks uninstallation half way through, and it's just going to sit like that for literally hours on my screen is going nowhere.

    So now, I've lost the perfectly good Photoshop CS6, who was the only program that worked very well. InDesign and Illustrator to open time and continued to come up with the message 'Error 5' who got asked to report in support, but nothing has been done about it.

    These are the programs stuck on my computer - I can not uninstall:

    Adobe Media Encoder CS6 - media encoder


    CS6 Adobe Bridge - Bridge CS6

    -Legal - Plug ins - Presets - required

    Adobe Extension Manager - Manager of extensions CS6

    -Legal - resources

    Adobe Creative cloud - creative


    However when I try to use the uninstaller of creative cloud, it comes up with this message:

    "Unable to d├⌐sinstaller the creative cloud to desktop. You have installed on your computer creative Cloud Applications that need. »

    Catch 22. I can not uninstall these other applications and cannot uninstall the creative cloud.

    Could someone at Adobe really help me solve these issues please?

    Thank you


    Adobe Application Manager is very essential application that manages processes such as Installation, download, activate, update, etc.

    Adobe Creative Cloud is nothing updated the version of Adobe Application Manager. Once you have installed Adobe Application Manager, it automatically had updated for Adobe Creative Cloud app, which is usual, no need to worry about fighting it.

    Regarding the process of uninstalling, have you tried cleaning Adobe tool?

    [Do not select clean all option unless absolutely necessary, because if the option clean up everything, it will remove all Adobe applications]

    Also, if you want to uninstall Adobe Creative Cloud app, you can use CCUn-install and try it once:

    Uninstall the Adobe Creative Cloud desktop application

    If you get the error 5 while apps launch even after uninstalling and reinstalling, make us know.

  • Allocate multiple cores of the only host for CPU on a virtual machine


    You don't know if it is possible, but could find is not online.

    An application on my virtual machine uses only a carrot and I want to accelerate.

    Add more cores on this virtual machine is meaningless, to that effect, I would like to allocate multiple cores of the host that will act as a single core on the virtual machine.

    Is this possible?

    Thank you


    As already stated above, this is not possible, and you have two options:

    1 buy a new CPU with a clock higher;

    2. that your application works with multiple processors.

  • Cannot start a virtual machine with more than 1 CPU socket added

    I've set up a few boxes of ESXi 5.5 with the free license in recent weeks, they have all been without problems so far. All 4 servers have the same exact hardware


    Dell Poweredge T620

    E5-2630 2 Intel CPU


    ESXi is installed on 2 x 146 GB 15 K SAS drives RAID-1

    Data for virtual machines store are 8 x 600 GB 10 K SAS RAID-10 disc

    Guest operating system is Server2012r2 on all virtual machines

    Installed it on ESXi 3 previous were conducted with custom ESXi 5.5 Dell without problem.

    The 4th is where I will have questions. I used the following ESXi installed just in case there is a bug somewhere

    5.5 of VMware ESXi

    ESXi 5.5 customized by Dell

    5.5 U1 of VMware ESXi

    Any version of the ESXi I use I can't have a virtual machine to begin with more than 1 CPU socket added to it. The virtual machine does not start even the VMWare BIOS. I tried the Bios EFI as well with no luck. The error message I get in the events is ' fatal error VMware ESX: vcpu (vcpu-X)-X:VM - entry failed; Valid VMCS (error code 8). The vcpu-X is always another. I have attached the log file is created. If I give the VM 1 single processor TI starts very well. I'm at a loss as to what could be the issue.

    Problem is solved. I caught another server with identical hardware, verified it worked properly, then started to swap parts between them. Turned out to be CPU1. Once this has been replaced from a working server I have not had any problems. Warranty has been appealed.

    Thanks for all the help!

  • Adding a virtual drive on the SCSI controller with sharing fails physical/virtual

    I have added a virtual disk to a SCSI controller with bus sharing physical or virtual, which is put down to the code below. Same code gets successfully if the bus share is 'noSharing '.

    $vmView = Vim::find_entity_view (view_type = > 'VirtualMachine', filter = > {name = > $vms [0]});
    $controllerKey = find_scsi_cntlrkey (vm = > $vmView, controller = > $cntlr);
    my hash % =)
    VM = > $vmView,
    diskMode = > 'persistent. "
    fileName = > $filename,
    controllerKey = > $controllerKey,
    unitNumber = > $target,
    size = > "5242880",.
    backingtype = > "ordinary."
    UUID = > UNDEF,
    deviceName = > UNDEF,
    My $filespec = get_vdiskSpec (%hash);
    print Dumper $filespec;
    My $vdisk = add_virtualdisk (vm = > $vmView, devspec = > $filespec);

    Run the command:

    [email protected]:~/scripts/VMware/apps$ perl - vmname vm1 - Server vcenter_server name of [email protected] past [email protected] generation add - 2, 2 - controller filename vm_232
    Addition of new LsiLogicSAS vSCSI 2 Controller to "vm1.
    Successfully added
    $VAR1 = bless ({}
    'fileOperation' = > bless ({}
    'val' = > 'create '.
    (}, 'VirtualDeviceConfigSpecFileOperation'),
    'operation' = > bless ({}
    'val' = > 'Add '.
    (}, 'VirtualDeviceConfigSpecOperation'),
    'device' = > ({bless him
    'capacityInKB' = > '5242880',.
    "backup" = > bless ({}
    'Filename' = > ' [datastore1 (4)]/vm1/vm_232.vmdk',)]
    'diskMode' = > 'persistent '.
    (}, "VirtualDiskFlatVer2BackingInfo").
    'unitNumber' = > 2,
    'controllerKey' = > '1002',.
    'key' = >-1
    (}, "VirtualDisk")
    (}, "VirtualDeviceConfigSpec");
    Cannot configure the virtual device.

    [email protected]:~/scripts/VMware/apps$

    In vcenter GUi I get below error:

    Has no power on scsi2:2.
    Cannot add the disk scsi2:2.

    But more successful if sharing of bus is none!

    [email protected]:~/scripts/VMware/apps$ perl - vmname vm1 - Server vcenter_server name of [email protected] past [email protected] generation add - 1:2 - filename vm_232 controller
    $VAR1 = bless ({}
    'fileOperation' = > bless ({}
    'val' = > 'create '.
    (}, 'VirtualDeviceConfigSpecFileOperation'),
    'operation' = > bless ({}
    'val' = > 'Add '.
    (}, 'VirtualDeviceConfigSpecOperation'),
    'device' = > ({bless him
    'capacityInKB' = > '5242880',.
    "backup" = > bless ({}
    'Filename' = > ' [datastore1 (4)]/vm1/vm1_232.vmdk',)]
    'diskMode' = > 'persistent '.
    (}, "VirtualDiskFlatVer2BackingInfo").
    'unitNumber' = > 2,
    'controllerKey' = > '1001'.
    'key' = >-1
    (}, "VirtualDisk")
    (}, "VirtualDeviceConfigSpec");
    Created virtual disk.
    [email protected]:~/scripts/VMware/apps$

    Can you get it someone please let me know, we should pass us any other parameter for the addition of SCSI controller with bus sharing physical/virtual disk?

    Thank you


    Yes, the stand is adjustable to all types at deployment time.  You need to change your disk with the correct support add operation.

Maybe you are looking for