ESXi Config-Backup with PowerCLI requires HTTP

There is a really useful and convenient PowerCLI one-liner for backing up the host configuration. I have been using it for years and had also explained this in detail in an old blogpost.

Get-Cluster -Name myCluster | Get-VMHost | Get-VMHostFirmware -BackupConfiguration -DestinationPath 'C:\myPath'

This is a command I always teach my students as part of my VMware courses. Backing up the host configuration is downright mandatory before making changes to the host, installing patches and drivers, or host updates. Just a few seconds of additional effort, but these configuration backups have saved me more than once from major trouble and many hours of extra work.

Recently, I was backing up host configurations in a major datacenter. Surprisingly, the command did not work on some of the vCenter instances and aborted with an error message.

Get-VMHostFirmware : 18.08.2023 12:05:49 Get-VMHostFirmware An error occurred while sending the request.
At line:1 char:28
+… et-VMHost | Get-VMHostFirmware -BackupConfiguration -DestinationPath …
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [Get-VMHostFirmware], ViError
+ FullyQualifiedErrorId : Client20_SystemManagementServiceImpl_BackupVmHostFirmware_DownloadError,VMware.VimAutomation.ViCore.Cmdlets.Commands.Host.GetVMHostFirmware

To understand the error, we must first understand how the PowerCLI command works. First, a backup of the host configuration is triggered on the host via vCenter. The host stores this locally as a zipped TAR archive (.tgz). The name is configBundle-HostFQDN.tgz (example: configBundle-esx01.lab.local.tgz). The archive is then downloaded from the host in a second step. The URL for this is:

http://[HostFQDN]/downloads/[Host-UUID]/configBundle-HostFQDN.tgz

By reading the error message above, there was obviously a problem with the download of the TGZ file. With the help of the network admins, it quickly became obvious what had happened. My workstation, from which I sent the PowerCLI command, tried unsuccessfully to establish an HTTP connection to the ESXi host. But this was blocked by a firewall rule.

I was wondering why the transfer is handled using unencrypted HTTP. In the log of the firewall you can see a connection attempt to the ESXi host with HTTP and HTTPS.

Is there a way to force the download using HTTPS?

My first thought was that there might be a parameter to the command that enforces the HTTPS protocol. A query in the VMTN forum unfortunately brought some disillusionment.

It is a bit surprising that VMware uses an unencrypted protocol for this sensitive data. All the more since the PowerCLI session to vCenter already runs over HTTPS anyway. The most plausible explanation would be that it was simply ‘forgotten’ to secure the transfer via SSL with this quite old command.

So currently there is no other choice but creating a firewall rule that allows downloading via HTTP.

VMware Explore 2023 Barcelona – Registration open

Starting now, you can register for VMware Explore EMEA in Barcelona.

There is a special discount for ‘early bird’ registrations through 7/31/2023. Those with a VMUG Advantage membership will receive an additional $100 discount.

As has been the case for many years, VMware Explore EMEA will once again be held in the halls of the Fira Gran Via in Barcelona.

Attendance is not free, but it’s priceless. See my former posts below about VMware Explore / VMworld and how it can supercharge your career.

Links

Here you can find a selection of my posts on previous VMware Explore and VMworld events.

VMware Explore EMEA 2022 – Review and Outlook

VMware-Explore EMEA is back

VMworld EU survival guide – 2019 Edition

German VMUG UserCon on 2023 in Frankfurt

There are only a few days left until the German VMUG UserCon opens its doors.

Following an old tradition, the event will take place again at Kap Europa near the main train station.

An extensive agenda with sessions from VMware and community speakers as well as interesting practical examples from partners on VMware integrations are on the agenda. In between, there will be enough coffee breaks to network with other visitors.

Save the Date

Thursday, June 29th 2023

8:30 – 18:00

Location

KAP Europa
Osloer Str. 5

Frankfurt am Main

Show in Google Maps…

Registration

UserCon participation is free of charge and requires only a VMUG membership (also free of charge).

Register here: German VMUG UserCon 2023

Agenda

Details and complete agenda

See you

Hope to meet you in Frankfurt.

TechX 300 Copenhagen – Powered by VMUGDK

2-days – Level 300 Event – September 20th and 21st

Join VMUG DK for an immersive experience where you’ll explore the intricacies of VMware’s cutting-edge technologies and gain in-depth insights from industry experts.

On 20th to 21st September VMUG DK will be hosting a Level 300 deep technical event in Copenhagen, and you are invited to join. Whether you’re an IT professional, a system administrator, or a technology enthusiast, TechX 300 is your gateway to unlocking the full potential of VMware solutions. Get ready to elevate your expertise and shape the future of virtualization at TechX 300!

This will be a hardcore technical event hosted by hardcore techies for hardcore techies. We consider this to be an extension of VMware Explore and the focus will be on creating the opportunities you need to interact with speakers and engineers in the Breakout, Lightning, and Community sessions, as well as at Meet-the-Experts, in smaller group discussions, in the Solution Exchange, and during the overall event.

These are some of the experts that have already confirmed for TechX300:

  • Cormac Hogan, Director and Chief Technologist – Cloud Infrastructure at VMware
  • Frank Denneman, Chief Technologist – Cloud Infrastructure at VMware
  • Johan Amersfoort, Technologist EUC & AI at ITQ
  • Katarina Brookfield, Staff Technical Marketing Architect for vSphere with Tanzu at VMware
  • Niels Hagoort, Staff Technical Marketing Architect for VMware Cloud at VMware
  • Mark Brookfield, Principal Technologist at Creative ITC

Let’s make it easy for you to join

If you are joining us from outside of Denmark, we will help make your trip and stay in Copenhagen as smooth as possible. Your local VMUG community can provide you with suggestions for hotels, restaurants, and optimal flights and you will also have the chance to travel as a group. Please reach out to your local community if you would like more information after registering for this event. If you are unsure about which local community you belong to, please feel free to reach out to VMUGDK, and we will assist you in finding the relevant contact information.

Attend the TechX 300 Copenhagen to:

  • Participate in technical deep dives led by a variety of industry experts
  • Expand your network with like-minded IT professionals
  • Learn about the latest products and solutions from trusted VMUG partners
  • Win cool SWAG & prizes

Location

Palads Cinema, Axeltorv 9, 1609 Copenhagen V

Call for community sessions

Calling all tech enthusiasts and subject matter experts! Are you passionate about a specific VMware-related topic within the realm of advanced technology? At TechX 300, we’re excited to offer the opportunity to showcase your expertise through our Level 300 Community Sessions.

We believe in the power of community-driven knowledge sharing, and that’s why we’re opening the doors for you to contribute to the event. To apply for a Level 300 Community Session, simply submit your session proposal highlighting the key takeaways, the target audience, and the VMware-specific expertise required.

Please fill out the form: Call for papers

Register

Register for TechX300