The builder builds a virtual machine by creating a new virtual machine from scratch, booting it, installing an OS, provisioning software within the OS, then shutting it down. The result of the VMware builder is a directory containing all the files necessary to run the virtual machine.

Here is a basic example.

This example is not functional. It will start the OS installer but then fail because we don't provide the preseed file for Ubuntu to self-install. Still, the example serves to show the basic configuration:. There are many configuration options available for the builder.

The builder uses expandable, not fixed-size virtual hard disks, so the actual file representing the disk will not use the full size unless it is full. By default this is set to about 40 GB.

This is chosen by default based on the disk adapter type. VMware tends to lean towards ide for the cdrom device unless sata is chosen for the disk adapter and so Packer attempts to mirror this logic.

This field can be specified as either ide, sata, or scsi. By default this is other. By specifying a more specific OS type, VMware may perform some optimizations or virtual hardware changes to better support the operating system running in the virtual machine.

Consult your platform for valid values. Only the default value has been tested, any other value is experimental. Default value is 9.

This is for advanced users only as this can render the virtual machine non-functional. See below for more information. If this is not specified then the VM will only contain a primary hard disk.

This option is for advanced usage, modify only if you know what you're doing. Some of the options you can specify are idesatanvme or scsi which uses the "lsilogic" scsi interface by default. If you specify another option, Packer will assume that you're specifying a scsi interface of that specified type.

This defaults to "disk". This option is for advanced usage. For ESXi, this defaults to zeroedthick. The available options for ESXi are: zeroedthickeagerzeroedthickthin. The type of the checksum can also be omitted and Packer will try to infer it based on string length. Here is a list of valid checksum values:.

Packer will try these in order. If anything goes wrong attempting to download or while downloading a single URL, it will move on to the next. All URLs must point to the same file same checksum. By default will go in the packer cache, with a hash of the original filename and checksum as its name.

This defaults to iso. The files in this directory will be available over HTTP that will be requestable from the virtual machine. This is useful for hosting kickstart files and so on. By default this is an empty string, which means no HTTP server will be started.

This is covered in more detail below. Because Packer often runs in parallel, Packer will choose a randomly available port in this range to run the HTTP server.

At first there will be all the required ports for vCenter server running on Windows system, and then bellow there will be required ports for vCenter server applicance 5. I hope you will find it useful. Of course you can directly access through the HTTPs, but this redirection can be helpfull if accessing in clear through https only.

Side Note: Make sure that you don't conflict with IIS or other webservers, which might also use port If there is another service, you might be wanting to change that. The LDAP service can run different ports.

The vCenter Server system needs to bind to porteven if you are not joining this vCenter Server instance to a Linked Mode group. If not already, open the firewall port. This port is also used for monitoring the data tranfer from SDK clients. You might want to use other port for https. In case you're conflicting with another port, you might want to change the other port to different one.

If another service is running on this port, it might be preferable to remove it or change its port to a different port. Port — Used for diplay the VMs console. There are many ports that are the same as in the Windows based vCenter server installation.

Connect with Certified Experts to gain insight and support on specific technology challenges including:. Experts Exchange is the only place where you can interact directly with leading experts in the technology field.

Web Dev. We help IT Professionals succeed at work. Last Modified: Hello, I have built up a test environment using an ESXi 5.

I am trying to backup the host with Veeam but receiving an error when trying to make a connection to the host. Portuser root, proxy srv port 0 The underlying connection was closed. An unexpected error occurred on a send Authentication failed because the remote party has closed the transport stream.

This server is not part of my existing Vcenter environment. Anything in that environment seems to connect with Veeam with no issues. I am able to ping this server by name, IP address and able to hit the web console from the Veeam server. I am not sure what the problem is here. Firewall is wide open and this is all internal communications. Nothing coming from the outside.

Any ideas? Start Free Trial. View Solutions Only. Author Commented: Sorry, I made a mistake in my original post. Not sure why as I can do that with all my other ESXi hosts on the same network. I think that could be the issue but not sure where I should be looking to correct. GG VP. Top Expert This award recognizes someone who has achieved high tech and professional accomplishments as an expert in a specific topic.

Commented: What is the Veeam version you are using? Can you please check the below article though it is bit old and update if that resolves your issue? What is the error you are getting when accessing the web console from Veeam server?This does not include port requirements for communication with services that run on previous version hosts, remote EMM Server, or other legacy processes.

NetBackup processes also use TCP ports for intra-host connects that are internal to the host. These ports do not need to be open externally. The ports may be bound and listening only for connections to the loopback interface In addition, some NetBackup processes also bind and listen on a random TCP port for local inter-process communication. Those port numbers will change each time the service is restarted, and also do not need to be open through the firewall.

These ports do not need to be open through the firewall unless pre This port number can be changed using the configureMQ command. Further, this feature reverses the direction of connection establishment between NetBackup servers and NetBackup clients.

The secure communication feature requires that all NB 8. Note: The web service proxy tunnel only transports communications for web services.

It is intended for certificate and CRL requests from clients - configured only for server-initiated file system backups - that do not have a network route to the master server but do have a network route to a media server. The secure communication feature also deprecates the use of Connect Options from NB 8. Options settings that enable legacy daemon ports, vnetd connect-back, legacy call-back, and reserved port use are ignored.

Unlike the older features, the TLS protocol occurs immediately upon connection establishment. Firewalls may detect and block this initial protocol and prevent connections to the web service. The CloudStore feature introduces a new service nbcssc which runs on master and media servers.

The new service listens, by default, on port which must be open inbound from the other NB servers and the OpsCenter hosts. This is meant primarily for media server to client.

But can also be configured for client-directed operations between the client and the master server, or between master and media server. The processes are also listening on TCP ports and respectively.Whether vCenter Server manages the host or it is a standalone ESXi host, different tools and access paths can do this.

For both tools, you do not need to install any software to your management workstation or laptop, and you can use Windows, Linux, or Mac. We will look at how to open a port in a second.

But before that, I'd like to point out that even if ESXi itself has a free version you can administer this way, it does not allow you to use backup software that can take advantage of VMware changed block tracking CBT and do incremental backups. But let's get back to our principal mission to show you how to access the firewall settings and open a closed firewall port.

You'll see that the VMware Host Client displays a list of active incoming and outgoing connections with the corresponding firewall ports. Note: When the rule is grayed out, it is disabled thus, you can enable it and vice versa. For some services, you can manage service details. Right-click a service and select an option from the pop-up menu.

Here is a view of the rule when you click it.

For some firewall rules, when you open the port, you also need to start the service. For example, after opening a firewall rule for the SNMP port, you'll need to go to the Services page and start and configure the service.

But you can only manage predefined ports. Can we create custom firewall ports? The answer is yes; however, you'll need to use the VMware command-line interface CLI for the job, and I'm not sure that's a supported scenario. While ESXi 5.

So it's up to you. To some extent, VMware locked out access to custom rules, but there are many predefined ones. Why not try out the predefined ones before going and creating custom ones? Another gotcha you might encounter is the fact you must configure these custom rules a certain way so they persist across reboots.

You'll need to be familiar with the vi Linux editor because you'll need to modify and create XML files—so it's not that easy of a task. I'm not saying it's not possible, but when it comes to support, I'm not sure VMware still supports it.

Your email address will not be published. Notify me of followup comments via e-mail. You can also subscribe without commenting. Receive new post notifications.

Server Fault is a question and answer site for system and network administrators. It only takes a minute to sign up.

They are configured like the following:. Why do I receive the wrong certificate? I can only assume that I need to configure the webConfigurator from pfSense to listen on a different port. If that's correct, how would I do that? It still does not work. Firebug still shows "Aborted" and I can't see any log messages from Pound. I then copied that and the private key to PoundVM and created a. The Cert value in the Pound config points to this file. Is that correct? But I installed it using apt Pound is new to me and I thought I could redirect the encrypted request to Tomcat.

You can't have it both ways. You mentioned that moving webConfigurator still doesn't allow this to work; my guess is that pfSense has some special magic applied to port to restrict admin access. You can either disable this magic, or do the much easier option and either run the NAT against a different port or a different IP. Of the two, a separate port is probably much, much easier. Let's say you picked for consistency with the Tomcat server. Now, all that said, you didn't explain how it is that you are decoding SSL here.

Varnish isn't going to work for SSL traffic. Thus, even once you get this working it Sign up to join this community. The best answers are voted up and rise to the top. Asked 6 years ago. Active 6 years ago. Viewed 2k times. The varnishlog shows a timeout.

I believe that this is the key. It seems that when I change the port of pfSenses' webConfigurator, I cannot reach behind it. Active Oldest Votes. I read that Varnish isn't able to cache SSL encrypted traffic, which is fine with me. SSL traffic is decrypted on the tomcat server directly. I just need Varnish to route the traffic through depending on the requested domain. Of course, it is used as a cache where possible.

Isn't Varnish capable of passing through SSL encrypted traffic at all?By using our site, you acknowledge that you have read and understand our Cookie PolicyPrivacy Policyand our Terms of Service. Server Fault is a question and answer site for system and network administrators. It only takes a minute to sign up. We are currently setting up a new vmware environement based on ESXi 5. After a lot of research maybe I didn't searched wellI couldn't manage to find which ports needs to be open between the vSphere client and the vCenter to get the communication ok and the vm consoles.

I found some articles but they are rather a list of all the used ports on VMWare. This looks like the doc you need. When you are connecting with the vSphere Client, the required ports depend on whether you connect directly to the ESXi host or you connect to a vCenter Server system.

The host process multiplexes port data to the appropriate recipient for processing. When the vSphere SDK is connected directly to ESXi, it can use this port to support any management functions related to the host and its virtual machines.

VMware does not support configuring a different port for these connections. This daemon multiplexes port data to the appropriate recipient for processing. VMware does not support configuring a different port for this connection. The vSphere Client uses this port to provide a connection for guest operating system MKS activities on virtual machines.

It is through this port that users interact with the guest operating systems and applications of the virtual machine.

Sign up to join this community. The best answers are voted up and rise to the top. Ports needed for the vSphere 5. Asked 6 years, 3 months ago. Active 6 years, 3 months ago. Viewed 32k times. Do you have any idea? Thanks in advance. MadHatter Nicolas Tourneur Nicolas Tourneur 31 1 1 gold badge 1 1 silver badge 2 2 bronze badges. You're google-foo is poor, we expect SF users to be able to find this kind of basic information before coming here, please consider this in any future questions.

This question kind of makes me angry, because it took me all of 30 seconds to find the answer in the vSphere 5.