View unanswered posts | View active topics It is currently Thu May 23, 2013 2:37 pm



Reply to topic  [ 8 posts ] 
 External Management 
Author Message

Joined: Tue Apr 21, 2009 12:25 pm
Posts: 33
Post External Management
Is there a way to use vSphere client to remotely access an ESX/ESXi box but only be allowed access to the controls (power on/off, mounting iso images) of a single VM, while not being allowed to edit other hardware settings?

We're looking at renting a VM from a local company (and by local, I mean on another island here in Hawaii), and in our negotiations, it's been stated that if Windows crashes to the point of re-install, we'll be charged for the re-install - which is totally understandable.

But I would like to avoid that charge if at all possible :) The only thing I've found in a quick google search was how to enable VNC in the vmx files themselves for 3.5.

Any thoughts?


Mon Oct 26, 2009 12:41 pm
Profile

Joined: Thu Oct 08, 2009 1:14 am
Posts: 20
Post Re: External Management
hello,

You can remotely control another ESXi through vSphere, for that you need to redirect the necessary ports.

TCP 443 443 vSphere client
TCP 902 902 VM console
TCP 903 903 VM console

You can also define a security policy for each VM and set a specific user.

To activate VNC, just edit the file of each VM and add:

remotedisplay.vnc.enabled = "TRUE"
remotedisplay.vnc.port = "5901" * change according to each VM
remotedisplay.vnc.password = "password"

Explain in detail what their plans.


Mon Oct 26, 2009 1:52 pm
Profile

Joined: Tue Apr 21, 2009 12:25 pm
Posts: 33
Post Re: External Management
specifically, I want to connect my copy of the vSphere client to an offsite ESXi box (easily done). The hard part is this: only be allowed access to the CONTROLS (power on/off) of a single VM, as well as only have the ability to connect various ISO images to the VM.

I played with my in house vSphere server and added a limited user account. I could see all of the (sample) setups VMWare included to limit user interaction, but I saw no way to customize these to suit my needs, unless I missed that option somewhere in the client?

I connect the client to a dedicated vSphere management server btw, if that helps.


Mon Oct 26, 2009 2:40 pm
Profile

Joined: Thu Oct 08, 2009 1:14 am
Posts: 20
Post Re: External Management
You have to create a new permission and associate the user who will be responsible for the VM.


Tue Oct 27, 2009 6:59 am
Profile
Site Admin

Joined: Mon Mar 16, 2009 10:13 pm
Posts: 3874
Post Re: External Management
You'll want to use roles and permissions http://www.vm-help.com/esx/esx3i/assign ... ssions.php.

_________________
Dave Mishchenko
VMware vExpert 2009-2012
Image
Now available - VMware ESXi: Planning, Implementation, and Security
Also available - vSphere Quick Start Guide


Tue Oct 27, 2009 2:00 pm
Profile

Joined: Tue Apr 21, 2009 12:25 pm
Posts: 33
Post Re: External Management
yeah I played with it yesterday after some digging, and it seems I would have to do the account 2 fold. I made a user for just the VM only, doing only what I want it to do. And it worked - for that VM. For the rest of the box, it had full access.

Do I have to first deny everything to that account, then allow specifics on the VM in question?


Tue Oct 27, 2009 2:02 pm
Profile
Site Admin

Joined: Mon Mar 16, 2009 10:13 pm
Posts: 3874
Post Re: External Management
If you create a role and grant a login that role on a VM, when they login, they'll see the host but will get a do not have permission message so they won't get any details about the host. They also won't see any VMs for which they don't have permissions. See the last image on the left of the above link.

_________________
Dave Mishchenko
VMware vExpert 2009-2012
Image
Now available - VMware ESXi: Planning, Implementation, and Security
Also available - vSphere Quick Start Guide


Tue Oct 27, 2009 2:20 pm
Profile

Joined: Tue Apr 21, 2009 12:25 pm
Posts: 33
Post Re: External Management
somehow I overlooked your previous post with the link - that looks like exactly what I need to do, thanks Dave!


Tue Oct 27, 2009 3:35 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 8 posts ] 

Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by STSoftware for PTF.