6.0.3

Table Of Contents
Prevent a Virtual Machine User or Process from Disconnecting Devices
Users and processes without root or administrator privileges within virtual machines have the capability to
connect or disconnect devices, such as network adaptors and CD-ROM drives, and the ability to modify
device seings. To increase virtual machine security, remove these devices. If you do not want to
permanently remove a device, you can prevent a virtual machine user or process from connecting or
disconnecting the device from within the guest operating system.
Prerequisites
Turn o the virtual machine.
Procedure
1 Find the virtual machine in the vSphere Web Client inventory.
a Select a data center, folder, cluster, resource pool, or host.
b Click the Related Objects tab and click Virtual Machines.
2 Right-click the virtual machine and click Edit .
3 Select VM Options.
4 Click Advanced and click Edit .
5 Verify that the following values are in the Name and Value columns, or click Add Row to add them.
Name Value
isolation.device.connectable.disabl
e
true
isolation.device.edit.disable
true
These options override any seings made in the guest operating system's VMware Tools control panel.
6 Click OK to close the Conguration Parameters dialog box, and click OK again.
Modify Guest Operating System Variable Memory Limit
You can increase the guest operating system variable memory limit if large amounts of custom information
are being stored in the conguration le.
Prerequisites
Turn o the virtual machine.
Procedure
1 Find the virtual machine in the vSphere Web Client inventory.
a Select a data center, folder, cluster, resource pool, or host.
b Click the Related Objects tab and click Virtual Machines.
2 Right-click the virtual machine and click Edit .
3 Select VM Options > Advanced and click Edit  .
4 Add or edit the parameter tools.setInfo.sizeLimit and set the value to the number of bytes.
5 Click OK.
Chapter 7 Securing Virtual Machines
VMware, Inc. 225