6.0.3

Table Of Contents
n
isolation.tools.ghi.autologon.disable
n
isolation.bios.bbs.disable
n
isolation.tools.hgfsServerSet.disable
6 Click OK.
Disable HGFS File Transfers
Certain operations such as automated tools upgrades use a component in the hypervisor called host guest
le system (HGFS). In high-security environments, you can disable this component to minimize the risk that
an aacker can use HGFS to transfer les inside the guest operating system.
Procedure
1 Find the virtual machine in the vSphere Web Client inventory.
a Select a data center, folder, cluster, resource pool, or host.
b Click the Related Objects tab and click Virtual Machines.
2 Right-click the virtual machine and click Edit .
3 Select VM Options.
4 Click Advanced and click Edit .
5 Verify that the isolation.tools.hgfsServerSet.disable parameter is set to TRUE.
When you make this change, the VMX process no longer responds to commands from the tools process.
APIs that use HGFS to transfer les to and from the guest operating system, such as some VIX commands or
the VMware Tools auto-upgrade utility, no longer work.
Disable Copy and Paste Operations Between Guest Operating System and Remote
Console
Copy and paste operations between the guest operating system and remote console are disabled by default.
For a secure environment, retain the default seing. If you require copy and paste operations, you must
enable them using the vSphere Web Client.
These options are set to the recommended value by default. However, you must set them to true explicitly if
you want to enable audit tools to check that the seing is correct.
Prerequisites
Turn o the virtual machine.
Procedure
1 Log into a vCenter Server system using the vSphere Web Client.
2 Right-click the virtual machine and click Edit .
3 Click VM Options, and click Edit .
4 Ensure that the following values are in the Name and Value columns, or click Add Row to add them.
Name Recommended Value
isolation.tools.copy.disable
true
isolation.tools.paste.disable
true
isolation.tools.setGUIOptions.enabl
e
false
These options override any seings made in the guest operating system’s VMware Tools control panel.
Chapter 7 Securing Virtual Machines
VMware, Inc. 223