A complete operational reference for vSphere 8.0.3 — architecture, virtual machine management, networking, storage, HA/DRS, security, PowerCLI, and troubleshooting for enterprise virtualization environments.
| Built-in Role | Access Level | Common Use |
|---|---|---|
| Administrator | Full access | vCenter admins only — not for day-to-day |
| Read-only | View only | Monitoring, auditors |
| Virtual Machine User | Interact with VMs | Console access, power ops |
| Virtual Machine Power User | VM + snapshot ops | Dev/test teams |
| Network Administrator | Network config | Network team |
| Datastore Consumer | Allocate space | Service accounts |
| No Cryptography Admin | Full minus crypto | Admins without key mgmt |
| Feature | vSS | VDS |
|---|---|---|
| Management | Per-host | vCenter-managed |
| Config scope | Host-local | Cluster-wide |
| Network I/O Control | No | Yes |
| Port mirroring | No | Yes |
| LACP | No | Yes |
| Traffic shaping | Egress only | Ingress + Egress |
| Private VLANs | No | Yes |
| Health check | No | Yes |
| License | Included | Enterprise Plus / vSphere+ |
| Type | Protocol | Use Case | Notes |
|---|---|---|---|
| VMFS 6 | FC / iSCSI / FCoE | Block — primary for VMs | Auto-unmap, 64TB volume, 62TB VMDK |
| NFS 4.1 | NFS over IP | File — shared storage | Session trunking (multipath), Kerberos auth |
| vSAN 8 | VMkernel (vSAN) | HCI — converged | Express Arch: NVMe-only, 64 disks/host |
| vVols | FC / iSCSI / NFS | Policy-based, per-VM | VASA provider on array required |
| RDM | FC / iSCSI | Raw device — DB / clusters | Physical or virtual compat mode |
| NVMe-oF | NVMe/TCP · NVMe/FC | Low-latency block | Supported in vSphere 8 |
| Port | Proto | Source | Destination | Service | Notes |
|---|---|---|---|---|---|
| 22 | TCP | Admin | ESXi | SSH | Disable when not in maintenance |
| 80 | TCP | Browser | ESXi/vCSA | HTTP redirect | Redirects to 443 |
| 443 | TCP | Client | vCSA / ESXi | HTTPS / vSphere Client | Primary management port |
| 902 | TCP/UDP | vCenter | ESXi | VMware Remote Console / NFC | VM console access, NFC data |
| 903 | TCP | Browser | ESXi | VMRC (legacy) | Remote console (older clients) |
| 2049 | TCP/UDP | ESXi | NAS | NFS | NFS datastore traffic |
| 3260 | TCP | ESXi | iSCSI array | iSCSI | Software iSCSI initiator |
| 5480 | TCP | Admin | vCSA | vCSA Appliance Mgmt UI | Backup, health, certificates |
| 5900 | TCP | Client | ESXi | VNC (disabled by default) | Legacy console — keep disabled |
| 6500 | UDP | ESXi | ESXi | HA agent (FDM) | vSphere HA heartbeats |
| 6501-6502 | TCP | ESXi | ESXi | HA agent (FDM) | FDM management |
| 7444 | TCP | vCenter | vCSA | SSO (STS) | vCenter Single Sign-On |
| 8000 | TCP | ESXi | ESXi | vMotion | Live VM migration traffic |
| 8100-8102 | TCP/UDP | ESXi | ESXi | Fault Tolerance (FT) | FT logging and sync traffic |
| 9000-9100 | TCP | ESXi | ESXi | vSAN | vSAN cluster traffic |
| 10000 | TCP | ESXi | ESXi | vSAN Health | vSAN health monitoring |
| 10080 | TCP | vCenter | ESXi | vSphere IO Filter | VAIO framework |
| 12321 | TCP | Admin | vCSA | vSphere API (REST) | Modern API endpoint |
| 44046 | TCP | ESXi | ESXi | vMotion (encrypted) | Encrypted vMotion stream |
| Metric | View (Key) | Threshold | Meaning |
|---|---|---|---|
| %RDY (CPU Ready) | CPU (c) | > 5% | vCPU waiting for physical CPU — VM oversized or host overloaded |
| %CSTP (Co-Stop) | CPU (c) | > 3% | SMP VMs waiting for all vCPUs to be scheduled together |
| %USED (CPU Used) | CPU (c) | > 90% sustained | Host physically running out of CPU cycles |
| MCTLSZ (Balloon) | Mem (m) | > 0 | Host reclaiming guest memory — host memory pressure |
| SWCUR (Swap) | Mem (m) | > 0 | Memory swapping to disk — severe performance degradation |
| DAVG/cmd (Disk latency) | Disk (d) | > 25ms | Average device latency — storage performance issue |
| KAVG/cmd (Kernel latency) | Disk (d) | > 2ms | Latency in VMkernel — queue depth or driver issue |
| DRPD (Packets dropped) | Net (n) | > 0 | Network packets dropped — NIC saturated or misconfigured |
| %MBPS (Bandwidth) | Net (n) | > 80% link | NIC approaching saturation — add uplinks or upgrade speed |