VMware 4817V62 Administration Guide - Page 36

Configuring a Windows Firewall to Allow a Specified Program Access

Page 36 highlights

vSphere Basic System Administration n When you install vCenter Server, ensure that the logged in user account has administrator privileges on the machine. n To resolve trust problems between a machine and the domain controller, remove the machine from the domain and then add it to the domain again. n To ensure that the Windows policy cache is updated, run the gpupdate /force command from the Windows command line. This command performs a group policy update. n If the local host cannot reach the remote host during a join operation, verify the following: n Remote vCenter Server IP address or fully qualified domain name is correct. n LDAP port on the remote vCenter Server is correct. n VMwareVCMSDS service is running. n Make sure your Windows and network-based firewalls are configured to allow Linked Mode. Configuring a Windows Firewall to Allow a Specified Program Access vCenter Server 4.0 uses Microsoft ADAM/AD LDS to enable Linked Mode, which uses the Windows RPC port mapper to open RPC ports for replication. When you install vCenter Server in Linked Mode, the firewall configuration on the local machine must be modified. Incorrect configuration of firewalls can cause licenses and roles to become inconsistent between instances. Prerequisites n The Windows version must be an earlier than Windows Server 2008. For Windows Server 2008, Windows automatically configures the firewall to permit access. n There must be no network-based firewalls between vCenter Server Linked Mode instances. For environments with network-based firewalls, see "Configuring Firewall Access by Opening Selected Ports," on page 36. Procedure 1 Select Start > Run. 2 Type firewall.cpl and click OK. 3 Make sure that the firewall is set to allow exceptions. 4 Click the Exceptions tab. 5 Click Add Program. 6 Add an exception for C:\Windows\ADAM\dsamain.exe and click OK. 7 Click OK. Configuring Firewall Access by Opening Selected Ports vCenter Server 4.0 uses Microsoft ADAM/AD LDS to enable Linked Mode, which uses the Windows RPC port mapper to open RPC ports for replication. When you install vCenter Server in Linked Mode, the firewall configuration on any network-based firewalls must be modified. Incorrect configuration of firewalls can cause licenses and roles to become inconsistent between instances. 36 VMware, Inc.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364

n
When you install vCenter Server, ensure that the logged in user account has administrator privileges
on the machine.
n
To resolve trust problems between a machine and the domain controller, remove the machine from
the domain and then add it to the domain again.
n
To ensure that the Windows policy cache is updated, run the
gpupdate /force
command from the
Windows command line. This command performs a group policy update.
n
If the local host cannot reach the remote host during a join operation, verify the following:
n
Remote vCenter Server IP address or fully qualified domain name is correct.
n
LDAP port on the remote vCenter Server is correct.
n
VMwareVCMSDS service is running.
n
Make sure your Windows and network-based firewalls are configured to allow Linked Mode.
Configuring a Windows Firewall to Allow a Specified Program Access
vCenter Server 4.0 uses Microsoft ADAM/AD LDS to enable Linked Mode, which uses the Windows RPC port
mapper to open RPC ports for replication. When you install vCenter Server in Linked Mode, the firewall
configuration on the local machine must be modified.
Incorrect configuration of firewalls can cause licenses and roles to become inconsistent between instances.
Prerequisites
n
The Windows version must be an earlier than Windows Server 2008. For Windows Server 2008, Windows
automatically configures the firewall to permit access.
n
There must be no network-based firewalls between vCenter Server Linked Mode instances. For
environments with network-based firewalls, see
“Configuring Firewall Access by Opening Selected
Ports,”
on page 36.
Procedure
1
Select
Start > Run
.
2
Type
firewall.cpl
and click
OK
.
3
Make sure that the firewall is set to allow exceptions.
4
Click the
Exceptions
tab.
5
Click
Add Program
.
6
Add an exception for
C:\Windows\ADAM\dsamain.exe
and click
OK
.
7
Click
OK
.
Configuring Firewall Access by Opening Selected Ports
vCenter Server 4.0 uses Microsoft ADAM/AD LDS to enable Linked Mode, which uses the Windows RPC port
mapper to open RPC ports for replication. When you install vCenter Server in Linked Mode, the firewall
configuration on any network-based firewalls must be modified.
Incorrect configuration of firewalls can cause licenses and roles to become inconsistent between instances.
vSphere Basic System Administration
36
VMware, Inc.