7.3

Table Of Contents
You need IIS 7.5 for Windows 2008 variants, IIS 8 for Windows 2012, and IIS 8.5 for Windows 2012
R2.
In addition to the configuration settings, avoid hosting additional Web sites in IIS.
vRealize Automation sets the binding on its communication port to all unassigned IP addresses,
making no additional bindings possible. The default vRealize Automation communication port is 443.
Table 26. IaaS Manager Service Host Internet Information Services
IIS Component Setting
Internet Information Services (IIS) roles
n
Windows Authentication
n
Static Content
n
Default Document
n
ASPNET 3.5 and ASPNET 4.5
n
ISAPI Extensions
n
ISAPI Filter
IIS Windows Process Activation Service
roles
n
Configuration API
n
Net Environment
n
Process Model
n
WCF Activation (Windows 2008 variants only)
n
HTTP Activation
n
Non-HTTP Activation (Windows 2008 variants only)
(Windows 2012 variants: Go to Features > .Net Framework 3.5 Features >
Non-HTTP Activation)
IIS Authentication settings Set the following non-defaults.
n
Windows Authentication enabled
n
Anonymous Authentication disabled
Do not change the following defaults.
n
Negotiate Provider enabled
n
NTLM Provider enabled
n
Windows Authentication Kernel Mode enabled
n
Windows Authentication Extended Protection disabled
n
For certificates using SHA512, TLS1.2 must be disabled on Windows 2012
variants
IaaS Manager Service Host
A Windows server that hosts the Manager Service component must meet additional requirements, in
addition to those for all IaaS Windows servers.
The requirements are the same, whether the Manager Service host is a primary or backup.
n
No firewalls can exist between a Manager Service host and DEM host. For port information, see IaaS
Windows Server Ports.
n
The Manager Service host must be able to resolve the NETBIOS name of the SQL Server database
host. If it cannot resolve the NETBIOS name, add the SQL Server NETBIOS name to the Manager
Service machine /etc/hosts file.
Installing vRealize Automation
VMware, Inc. 28