vmware

VMware Workstation Performance enhancements

Posted on Updated on

There can be a multitude of factors that could impact performance of your Workstation VMs. Running a VCF 9 stack on VMware Workstation demands every ounce of performance your Windows 11 host can provide. To ensure a smooth lab experience, certain optimizations are essential. In this post, I’ll walk through the key adjustments to maximize efficiency and responsiveness.

Note: There are a LOT of settings I did to improve performance. I take a structured approach by trying things slowly vs. applying all. The items listed below are what worked for my system and it’s recommend for that use case only. Unless otherwise stated, the VM’s and Workstation were powered down during these adjustments.

Items recently covered in my VMware Workstation Gen 9: BOM1 deployment.

  • Host BIOS/UFEI Settings
    • Check out my blog under the ‘BIOS settings’ for more information.
  • Hardware Design:
    • Fast Storage: NVMe, SSD, and U.2 all contribute to VM performance
    • Placement of VM files: We placed and isolated our ESX VMs on specific disks which helps to ensure better performance
    • PCIe Placement: Using the system block diagram I placed the devices in their optimal locations
    • Ample RAM: Include more than enough RAM to support the VCF 9 VMs
    • CPU cores: Design enough CPU cores to support the VCF 9 VMs
    • Video Card: Using a power efficient GPU can help boost VM performance
  • VM Design
    • Disk Choices: Matched the VM disk type to the physical drive type they are running on. Example – NVMe physical to a VMs NVMe disk
    • CPU Settings: Match physical CPU Socket(s) to VM CPU settings.
    • vHardware Choices: When creating a VM, Workstation should auto-populate hardware settings. Best vNIC to use is the vmxnet3. You can use the Guest OS Guide to validate which virtual hardware devices are compatible.
  • Fresh Installs
    • There’s nothing like a fresh install of the base OS to be a reliable foundation for performance improvments.
    • When Workstation is installed it adapts to the base OS. There can be performance gains due to this adaption.
  • Disable Side-Channel Mitigations (Core Isolation)
    • Disabling these can boost performance, especially on older processors, but may reduce security.

New Items to help with performance

Exclude Virtual Machine Directories From Antivirus Tools

NOTE — AV exceptions exclude certain files, folders, and processes from being scanned. By adding these you can improve Workstation performance but there are security risks in enabling AV Exceptions. Users should do what’s best for their environment. Below is how I set up my environment.

  • Script:
  • Manual Steps:
    • Open Virus and Threat Protection
    • Virus & threat protection settings > Manage Settings
    • Under ‘Exclusion’ choose ‘Add or remove exclusions’
    • Click on ‘+ Add an exclusion’
    • Choose your type (File, Folder, File Type, Process)
    • File Type: Exclude these specific VMware file types from being scanned: 
      • .vmdk: Virtual machine disk files (the largest and most I/O intensive).
      • .vmem: Virtual machine paging/memory files.
      • .vmsn: Virtual machine snapshot files.
      • .vmsd: Metadata for snapshots.
      • .vmss: Suspended state files.
      • .lck: Disk consistency lock files.
      • .nvram: Virtual BIOS/firmware settings. 
    • Folder: Exclude the following directories to prevent your antivirus from interfering with VM operations 
      • VMware Installation folder
      • VM Storage Folders: Exclude the main directory where you store your virtual machines
      • Installation Folder: Exclude the VMware Workstation installation path (default: C:\Program Files (x86)\VMware\VMware Workstation\).
      • VMware Tools: If you have the VMware Tools installation files extracted locally, exclude that folder as well. 
    • Process: Adding these executable processes to your antivirus exclusion list can prevent lag caused by the AV monitoring VMware’s internal actions: 
      • vmware.exe: The main Workstation interface.
      • vmware-vmx.exe: The core process that actually runs each virtual machine.
      • vmnat.exe: Handles virtual networking (NAT).
      • vmnetdhcp.exe: Handles DHCP for virtual networks.

Power Plan

Typically by default Windows 11 has the “Balanced” Power plan enabled. Though these settings are good for normal use cases, using your system as a dedicated VMware Workstation requires a better plan.

Below I show 2 ways to adjust a power plan. 1) Using a script to create a custom plan or 2) manually make similar adjustments.

  • 1) Script: I created a script that creates a custom power plan named “VMware Workstation Performance Plan” and makes all the needed changes for my system. You can find my blog here.
  • 2) Manual Adjustments:
    • Open the power plan. Control Panel > Hardware and Sound > Power Options > Change settings that are currently unavailable
    • You might see on every page “Change settings that are currently unavailable”, just click on it before making changes.
    • Set Power Plan:
      • Click on ‘Hide Additional Plans’.
      • Choose either “Ultimate Performance” or “High Performance” plan and then click on “Change plan settings”
      • Hard Disk > 0 Minutes
      • Wireless Adapter Settings > Max Performance
      • USB > Hub Selective Suspend Time out > 0
      • PCI Express > Link State Power Management > off
      • Processor power management > Both to 100%
      • Display > Turn off Display > Never

Lastly, make sure the correct power plan is active. I used the commands ‘powercfg -list’ to show the active plan and then ‘powercfg -setactive GUID’, replacing GUID with the plan I wanted.

Power Throttling (Not very common)

Power throttling in Windows 11 is an intelligent, user-aware feature that automatically limits CPU resources for background tasks to conserve energy and extend battery life. By identifying non-essential, background-running applications, it reduces power consumption without slowing down active, foreground apps.

To determine if it is active go in to System > Power and look for Power Mode

If you are using a high performance power plan usually this feature is disabled.

If you are running a power plan where this is enabled, and you don’t want to disable it, then you can maximize your performance by disabling power throttling for the Workstation executable.

powercfg /powerthrottling disable /path “C:\Program Files (x86)\VMware\VMware Workstation\x64\vmware-vmx.exe”

Sleep States

Depending on your hardware you may or may not have different Sleep states enabled. Ultimately, for my deployment I don’t want any enabled.

To check if any are from a command prompt type in ‘powercfg /a’ and adjust as needed.

Workstation Memory Page files

In my design I don’t plan to overcommit physical RAM (640GB ram) for my nested VM’s. To maximize the performance and ensure VMware Workstation uses the physical memory exclusively, I follow these steps: Configure global memory preferences, Disable Memory Trimming for each VM, Force RAM-Only Operation, and adjust the Windows Page Files.

Configure Global Memory Preferences

  • This setting tells VMware how to prioritize physical RAM for all virtual machines running on the host. 
    • Open Workstation > Edit > Preferences > Memory
    • In the Additional memory section, select the radio button for “Fit all virtual machine memory into reserved host RAM”.

Disable Memory Trimming for each VM:

  • Windows and VMware use “trimming” to reclaim unused VM memory for the host. Since RAM will not be overallocated, I disable this to prevent VMs from ever swapping to disk.
    • Right-click your VM and select Settings
    • Go to the Options tab and select the Advanced category.
    • Un-Check the box to disable memory page trimming.
    • Click OK and restart the VM

Force RAM-Only Operation (config.ini):

  • This is an advanced step that prevents VMware from creating .vmem swap files, forcing it to use physical RAM or the Windows Page File instead.
  • Close VMware Workstation completely.
  • Navigate to C:\ProgramData\VMware\VMware Workstation\ in File Explorer (Note: ProgramData is a hidden folder).
  • Open the file named config.ini with Notepad (you may need to run Notepad as Administrator).
  • Add the following lines to the end of the file:
    • mainMem.useNamedFile = “FALSE”
    • prefvmx.minVmMemPct = “100”
  • Save the file and restart your computer

Windows Page Files

  • With 640GB of RAM Windows 11 makes a huge memory page file. Though I don’t need one this large I still need one for crash dumps, core functionality, and memory management. According to Microsoft, for a high-memory workstation or server, a fixed page file of 16GB to 32GB is the “sweet spot.” I’m going a bit larger.
  • Go to System > About > Advanced system Settings
  • System Properties window appears, under Performance choose ‘Settings’
  • Performance Options appears > Advanced > under Virtual memory choose ‘change’
  • Uncheck ‘Automatically manage paging…’
  • Choose Custom size, MIN 64000 and MAX 84000
  • Click ‘Set’ > OK
  • Restart the computer

Windows Visual Effects Performance

The visual effects in Windows 11 can be very helpful but they can also minimally slow down your performance. I prefer to create a custom profile and only enable ‘Smooth edges of screen fonts’

  • Go to System > About > Advanced system Settings
  • System Properties window appears,
  • On the Advanced Tab, under Performance choose ‘Settings’
  • On the Visual Effect tab choose ‘Custom’ and I chose ‘Smooth edges of screen fonts’

Disable BitLocker

Windows 11 (especially version 24H2 and later) may automatically re-enable encryption during a fresh install or major update. By default to install Windows 11 it requires TPM 1.2 or higher chip (TPM 2.0 recommended/standard for Win11), and UEFI firmware with Secure Boot enabled. BitLocker uses these features to “do its work”. To disable I do the following.

  • Registry Edit (Post-Installation – may already be set):
    • Press Win + R, type regedit, and press Enter
    • Navigate to: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker
    • Right-click in the right pane, select New > DWORD (32-bit) Value
    • Name it PreventDeviceEncryption and set its value to 1
    • Disable the Service:
      • Press Win + R, type services.msc, and press Enter.
      • Find BitLocker Drive Encryption Service.
      • Right-click it, select Properties, set the “Startup type” to Disabled, and click Apply.

Clean out unused Devices:

Windows leaves behind all types of unused devices that are hidden from your view in device manager. Though these are usually pretty harmless its a best practice to clean them up from time to time.

The quickest way to do this is using a tool called Device Cleanup Tool. Check out my video for more how to with this tool.

Here is Device Cleanup Tool running on my newly (<2 months) installed system. As you can see unused devices can build up even after a short time frame.

Debloat, Clean up, and so much more

There are several standard Windows based features, software, and cleanup tools that can impact the performance of my deployment. I prefer to run tools that help optimize Windows due to their ability to complete tasks quickly. The tool I use to debloat and clean up my system is Winutil. It’s been a proven util for not only optimizing systems, installing software, updates, but helping to maintain them too. For more information about Winutil check out their most recent update.

For ‘Tweaking’ new installs I do the following:

  • Launch the WinUtil program
  • Click on Tweaks
  • Choose Standard
  • Unselect ‘Run Disk Cleanup’
  • Click on Run Teaks

Additionally, you may have noticed Winutil can create an Ultimate Preforamnce power plan. That may come in handy.

Remove Windows Programs:

Here is a list of all the Windows Programs I remove, they are simply not needed for a Workstation Deployment. Some of these can be removed using the WinUtil most I remove with Revo Uninstaller Free Edition.

  • Cortana
  • Co-polit
  • Camera
  • Game Bar
  • Teams
  • News
  • Mail and Calendar
  • Maps
  • Microsoft OneDrive
  • Microsoft to do
  • Movies and TV
  • People
  • Phone Link
  • Solitare
  • Sticky Notes
  • Tips
  • Weather
  • Xbox / xbox live

References and Other Performance Articles:

VMware Cloud Foundation 9.1 (VCF 9.1) key events, webinars, and Resources

Posted on Updated on

Below is a summary of some of the great announcements around the VCF 9.1 release.

Discover What’s New in VCF 9.1

Watch this recording to see the new features in action through demo-walkthroughs and discover how the newly announced partnerships will expand VCF 9.1 capabilities.

Modules:

Learn More

Strategic Roadmap & Training

The following schedule outlines key opportunities to engage with VCF experts and the broader Broadcom ecosystem in 2026. The marquee event, VMware Explore 2026, returns to Las Vegas in late August.

DateEvent / Webinar NameLocation / Type
May 5, 2026Broadcom’s VMware in 2026: VCF 9, Containers, and AIWebinar (On-Demand)
May 13-15, 2026VCF Experience Day (Hosted by TD SYNNEX)Dallas/Plano, TX
Aug 31 – Sep 3, 2026VMware Explore 2026 Las VegasLas Vegas, NV
Sep 29-30, 2026VMware Explore on Tour: MumbaiMumbai, India
Oct 1-2, 2026VMware Explore on Tour: SingaporeSingapore
Oct 13-14, 2026VMware Explore on Tour: FrankfurtFrankfurt, Germany

Virtually Speaking Podcast Series and others

Hosted by Pete Flecha and John Nicholson, the Virtually Speaking Podcast provides weekly technical deep dives into the VCF 9.1 ecosystem. The new “VCF 9 Core” series features product engineers explaining the architectural changes.

Episode 1: Introducing VCF 9.1: Built for Efficiency and ResilienceEpisode 6: VCF 9.1: From AI Hype to Production Reality
Episode 2: From Infrastructure to Innovation: VCF 9.1 Core ExplainedEpisode 7: VCF 9.1: Scaling Secure Edge Deployments
Episode 3: VCF 9.1: Automation, Kubernetes APIs, and Faster DeploymentsEpisode 8: VCF 9.1 Cyber Resilience: From Attack to Recovery with Confidence
Episode 4: Inside VCF 9.1: Platform, Lifecycle, and What’s Different NowEpisode 9: Designing VCF 9.1: Architecture, Sizing, and Scale in Practice
Episode 5: From Rising Costs to Smarter Storage: The VCF 9.1 Reality

Resources & Documentation

Critical Reference Materials

  • Product News Release: Broadcom Announces VMware Cloud Foundation 9.1
  • Broadcom TechDocs: TechDocs have been completed updated making it easier to find content.
  • Release Notes: The full VCF 9.1 Release Notes detail the specific upgrade paths from VCF 5.x.
  • VCF Import Guide: Technical documentation on how to prepare brownfield vSphere clusters for ingestion.
  • Private AI Reference Architecture: A comprehensive guide on sizing GPU clusters and configuring vSAN ESA for high-throughput AI training.

Tech Blogs

Coming Soon

HOL

  • Test-Drive VCF 9.1 and more for free
  • What’s New in VCF 9.1
  • Memory Tiering in VCF 9.1
  • Native Kubernetes Workloads on VCF 9.1

Solution Architecture Guides

  • Self-Service Multi-tenant Private Cloud Consumption
  • Private AI Service Deployment and Consumption with VCF 9.1
  • VCF Edge Design for Retail, Manufacturing
  • Flexible Storage Deployment Models

Next Steps

For organizations planning their upgrade path, the immediate next step is to audit current hardware compatibility against the VCF 9.1 HCL (Hardware Compatibility List), particularly if planning to leverage the new NVMe memory tiering capabilities.

REF: See the follow URL for more updates. https://go-vmware.broadcom.com/whats-new-in-vcf

Managing the SDDC Installer admin@local Account – Password Resets and lockouts

Posted on

We’ve all been there. We deploy an appliance and then we can’t find the password. We try to log in a few times and the accout gets locked out. For administrators managing VMware Cloud Foundation (VCF), the admin@local account is a critical account. Introduced to provide access to the SDDC Manager APIs and the VCF Installer even when the management vCenter Server or Identity Provider (SSO) is unavailable, it ensures you aren’t locked out of your environment during critical failures.

Phase 1: Resetting the Forgotten Password

If you don’t know the current password, you must manually inject a new one via the SDDC Manager console. This process involves creating a secure credential file and hashing your new password using OpenSSL.

According to KB 403099, follow these steps on the SDDC Manager VM:

  1. Access the Console: Log in to the SDDC Manager via SSH as the vcf user, then switch to root: su - or simply logon as root.
  2. Initialize the Security Directory: Ensure the local security directory exists with the correct permissions:
    mkdir -p /etc/security/local chown root:vcf_services /etc/security/local && chmod 650 /etc/security/local
  3. Create the Password File: Create an empty file to house the secret:
    echo -n "" > /etc/security/local/.localuserpasswd chown root:vcf_services /etc/security/local/.localuserpasswd && chmod 660 /etc/security/local/.localuserpasswd
  4. Generate the New Password: Replace You Password here in the command below with a password that meets the VCF requirements (12-127 characters, including uppercase, lowercase, numbers, and special characters):
    echo -n 'Your Password Here' | openssl dgst -sha512 -binary | openssl enc -base64 | tr -d '\n' > /etc/security/local/.localuserpasswd
  5. Restart Services: Apply the change by restarting the SDDC Manager services:
    /opt/vmware/vcf/operationsmanager/scripts/cli/sddcmanager_restart_services.sh

Phase 2: Unlocking the Account

Even with a fresh password, if the account was previously locked due to too many failed attempts, the system may still reject your login. You must now clear the lockout state.

Based on KB 403316, you can clear the lockout by restarting the common services component:

  1. Stay in the Console: From your existing root session on the appliance (or via the VCF Installer appliance if that is where the lockout occurred).
  2. Clear the Lockout: Run the following command to restart the service responsible for authentication:
    systemctl restart commonsvcs
  3. Final Verification: Wait a moment for the service to initialize, then attempt to log in to the web interface using the new password you created in Phase 1.

Summary

When you are locked out of your VCF environment and have forgotten your credentials, the path to recovery is a two-step process. By first following KB 403099 to manually reset the password via the command line, and then following KB 403316 to restart the commonsvcs and clear the lockout, you can regain control of your SDDC Manager and VCF Installer.

Deploying the ASUSTOR DRIVESTOR 4 Pro Gen 2 | AS3304T v2

Posted on Updated on

For years, my trusty DRIVESTOR 2 Pro was the heartbeat of our home. From kids navigating online school to adults working from home, it served as our essential, daily hub for family backups. Unfortunately, a sudden power event had other plans for it.

While I was lucky enough to have my data backed up elsewhere. In this post, I’ll walk you through how these two models compare, share some photos of the new hardware, and show you exactly how I got my new setup up and running.

Device Compare

ASUSTOR AS3302T (Gen 1)ASUSTOR AS3304T v2 (Gen 2)
Drive Bays 2 x 3.5″/2.5″ SATADrive Bays 4 x 3.5″/2.5″ SATA
Processor Realtek RTD1296 (1.4GHz Quad-Core)Processor Realtek RTD1619B (1.7GHz Quad-Core)
Memory (RAM) 2GB DDR4 (Non-expandable)Memory (RAM) 2GB DDR4 (Non-expandable)
Networking 1 x 2.5-Gigabit EthernetNetworking 1 x 2.5-Gigabit Ethernet
USB Ports 3 x USB 3.2 Gen 1USB Ports 3 x USB 3.2 Gen 1
Btrfs Support No (EXT4 only)Btrfs Support Yes (Snapshots supported)
RAID OptionsSingle, JBOD, RAID 0, 1RAID OptionsSingle, JBOD, RAID 0, 1, 5, 6, 10
FAN/Size 1 x 70mm
Standby/Idle Noise 19db
Active Operation Noise 32db
FAN/Size 1 x 120mm
Standby/Idle Noise 19.7db
Active Operation Noise 32db
Power Consumption 12.3W (Operation)Power Consumption 25.1W (Operation)
Dimensions 170(H) x 114(W) x 230(D) mmDimensions 170(H) x 174(W) x 230(D) mm

Key Improvements in the AS3304T v2

  • Processor & GPU: The v2 uses the newer RTD1619B chip. It is roughly 20% faster in clock speed and features an upgraded iGPU, which provides significantly better 4K transcoding for media players like Plex.
  • Modern File System (Btrfs): A major software upgrade for the v2 models is the addition of Btrfs support. This enables Snapshots, which protect your data against accidental deletion or ransomware by allowing you to “roll back” to a previous state.
  • Storage Flexibility: Beyond having twice the bays, the AS3304T v2 supports RAID 5 and 6. These configurations offer a better balance of high capacity and data redundancy compared to the RAID 1 limit of the 2-bay AS3302T

Product Photo

Initial Setup

I plugged in the power and the network cable into the device and allowed it to get a DCHP address. To find the address assigned I downloaded and scanned my network with the ASUSTOR Control Center (acc.asustor.com). One I knew the IP address I went to it on port 8001.

When I first entered the web interface I was welcomed by the main screen. One important note is the orange initialization statement. It notes your drive will be erased and a warning to backup your data.

One thing I like about the initial setup is the ability to update the ADM (ASUSTOR Data Master) version. I allowed it to update as I was doing my install.

After I made all my selections, then ADM completes it pre-tasks.

Next, the T&Cs are presented.

I get to choose my system appearance.

I entered my information.

The system does its final initialization.

I enter in my ASUSTOR ID and then on next page put in your Contact information, region, and language

All done!

Back in the web interface, I’m prompted to adjust my http and https ports. I change them from the defaults of 8000 and 8001.

The ADM guide appears and it is a good way to learn where things are. I’m not going through all 6 steps but just know its a very hand tool.

Here is what the first one looks like.

It actually takes you step by step.

Once I exit the ADM guide, I first set up my network address. Settings > Network > change to manual IP > enter my IP and save it. The web interface reboots into the new IP. Additionally, I disabled IPv6.

Next I go into the Storage Manager and validate my disks. It also gives me a status of the RAID 5 initialization.

Then in Access Control I’ll setup a few user accounts.

While in Access Control, I setup shared folder. The add shared folder window appears, I name my share, select access ‘by user’, choose the user and their access rights, chose to encrypt of not, and click on finish to complete the process.

From my experience ADM is a very intuitive and easy to learn. Speaking of learning, ASUSTOR has a FREE NAS Tutorial that explains how to use it! I’ve used it quite a bit is worth a look.

While losing my original DRIVESTOR 2 Pro was a headache, the jump to the DRIVESTOR 4 Pro Gen 2 has been a massive silver lining. With the extra drive redundancy of RAID 5, I feel much more secure about our family’s digital files. It’s faster, quieter, and handles our school and work-from-home needs without breaking a sweat. If you’re looking for a NAS that balances power with a genuinely easy learning curve, ASUSTOR remains my top recommendation.

Using PowerShell to setup AV exceptions for Workstation 25H2u1 and Windows 11

Posted on Updated on

Adding AV exceptions to your Workstation deployment on Windows 11 can really improve the overall performance. In this blog post I’ll share my exclusion script recently used on my environment.

NOTE: You cannot just cut, paste, and run the script below. There are parts of the script that have to be configured for the intended system.

What the script does.

  • For Windows 11 users with Microsoft’s Virus & threat protection enabled this script will tell AV to not scan specific file types, folders, and processes related to VMware Workstation.
  • It will ignore exceptions that already exist.
  • It will display appropriate messages (Successful, or Already Exists) as it completes tasks.

What is the risk?

  • Adding an exception (or exclusion) to antivirus (AV) software, while sometimes necessary for application functionality, significantly lowers the security posture of a device. The primary risk is creating a security blind spot where malicious code can be downloaded, stored, and executed without being detected.
  • Use at your own risk. This code is for my personal use.

What will the code do?

It will add several exclusions listed below.

  • File Type: Exclude these specific VMware file types from being scanned: 
    • .vmdk: Virtual machine disk files (the largest and most I/O intensive).
    • .vmem: Virtual machine paging/memory files.
    • .vmsn: Virtual machine snapshot files.
    • .vmsd: Metadata for snapshots.
    • .vmss: Suspended state files.
    • .lck: Disk consistency lock files.
    • .nvram: Virtual BIOS/firmware settings. 
  • Folder: Unique to my deployment it will exclude the following directories to prevent your antivirus from interfering with VM operations 
    • VMware Installation folder
    • VM Storage Folders: Exclude the main directory where I store my virtual machines.
    • Installation Folder: Exclude the VMware Workstation installation path ((default: C:\Program Files (x86)\VMware\VMware Workstation).
  • Process:
    • vmware.exe: The main Workstation interface.
    • vmware-vmx.exe: The core process that actually runs each virtual machine.
    • vmnat.exe: Handles virtual networking (NAT).
    • vmnetdhcp.exe: Handles DHCP for virtual networks.

The Script

Under the section ‘#1. Define your exclusions ‘ is where I adapted this code to match my environment

# Check for Administrator privileges
if (-not ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
Write-Warning "Please run this script as an Administrator."
break
}

# 1. Define your exclusions

# This is where you put in YOUR folder exclusions
$folders = @("C:\Program Files (x86)\VMware\VMware Workstation", "D:\Virtual Machines", "F:\Virtual Machines", "G:\Virtual Machines", "H:\Virtual Machines", "I:\Virtual Machines", "J:\Virtual Machines", "K:\Virtual Machines", "L:\Virtual Machines")

# These are the common process exclusions

$processes = @("C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe", "C:\Program Files (x86)\VMware\VMware Workstation\x64\vmware-vmx.exe", "C:\Program Files (x86)\VMware\VMware Workstation\vmnat.exe", "C:\Program Files (x86)\VMware\VMware Workstation\vmnetdhcp.exe")

# These are the common extension exclusions

$extensions = @(".vmdk", ".vmem", ".vmsd", ".vmss", ".lck", ".nvram")

# Retrieve current settings once for efficiency
$currentPrefs = Get-MpPreference
Write-Host "Checking and applying Windows Defender Exclusions..." -ForegroundColor Cyan

# --- Validate and Add Folders ---
foreach ($folder in $folders) {
if ($currentPrefs.ExclusionPath -contains $folder) {
Write-Host "Note: Folder exclusion already exists, skipping: $folder" -ForegroundColor Yellow
} else {
Add-MpPreference -ExclusionPath $folder
Write-Host "Successfully added folder: $folder" -ForegroundColor Green
}
}

# --- Validate and Add Processes ---
foreach ($proc in $processes) {
if ($currentPrefs.ExclusionProcess -contains $proc) {
Write-Host "Note: Process exclusion already exists, skipping: $proc" -ForegroundColor Yellow
} else {
Add-MpPreference -ExclusionProcess $proc
Write-Host "Successfully added process: $proc" -ForegroundColor Green
}
}

# --- Validate and Add Extensions ---
foreach ($ext in $extensions) {
if ($currentPrefs.ExclusionExtension -contains $ext) {
Write-Host "Note: Extension exclusion already exists, skipping: $ext" -ForegroundColor Yellow
} else {
Add-MpPreference -ExclusionExtension $ext
Write-Host "Successfully added extension: $ext" -ForegroundColor Green
}
}

Write-Host "`nAll exclusion checks complete." -ForegroundColor Cyan

The Output

In the output below, when the script creates an item successfully it will show in green. If it detects a duplicate it will output a message in yellow. I ran the script with a .vmdk exclusion already existing to test it out.

When its complete the AV exclusions in Windows should looks similar to the partial screenshot below.

To view the exclusions, in Win 11 open ‘Virus & Threat Protection’ > Manage Settings > Under Exclusions chose ‘Add or remove exclusion’

Upgrading Workstation 25H2 to 25Hu1

Posted on Updated on

Last February 26 2026 VMware released Workstation Pro 25H2u1. It’s an update that does repair a few bugs and security patches. In this blog I’ll cover how to upgrade it.

Helpful links

Meet the Requirements:

When installing/upgrading Workstation on Windows most folks seem to overlook the requirements for Workstation and just install the product. You can review the requirements here.

There are a couple of items folks commonly miss when installing Workstation.

  • The number one issue is Processor Requirements for Host Systems . It’s either they have a CPU that is not supported or they simply did not enable Virtualization support in the BIOS.
  • The second item is Microsoft Hyper-V enabled systems. Workstation supports a system with Hyper-V enabled but for the BEST performance its best to just disable these features.
  • Next, if you’ve upgraded your OS but never reinstall Workstation, then its advised to uninstall then install Workstation.
  • Lastly, if doing a fresh OS install ensuring drivers are updated and DirectX is at a supportable version.

How to download Workstation

Download the Workstation Pro 25H2u1 for Windows. Make sure you click on the ‘Terms and Conditions’ AND check the box. Only then can you click on the download icon.

Choose your install path

Before you do a fresh install:

If you are upgrading Workstation, review the following:

  • Ensure your environment is compatible with the requirements
  • If you have existing VMs:

Note: If you are upgrading the Windows OS or in the past have done a Windows Upgrade (Win 10 to 11), you must uninstall Workstation first, and then reinstall Workstation. More information here.

Upgrading Workstation 25H2 to 25Hu1

Run the download file, wait a min for it to confirm space requirements, then click Next

Accept the EULA.

Compatible setup check

Confirm install directory

Check for updates and join the CEIP program.

Allow it to create shortcuts

Click Upgrade to complete the upgrade

Click on Finish to complete the Wizard.

Lastly, check the version number of Workstation. Open Workstation > Help > About

My Silicon Treasures: Mapping My Home Lab Motherboards Since 2009

Posted on Updated on

I’ve been architecting home labs since the 90s—an era dominated by bare-metal Windows Servers and Cisco products. In 2008, my focus shifted toward virtualization, specifically building out VMware-based environments.  What began as repurposing spare hardware for VMware Workstation quickly evolved. As my resource requirements scaled, I transitioned to dedicated server builds. Aside from a brief stint with Gen8 enterprise hardware, my philosophy has always been “built, not bought,” favoring custom component selection over off-the-shelf rack servers.  I’ve documented this architectural evolution over the years, and in this post, I’m diving into the the specific motherboards that powered my past home labs.

Gen 1: 2009-2011 GA-EP43-UD3L Workstation 7 | ESX 3-4.x

Back in 2009, I was working for a local hospital in Phoenix and running the Phoenix VMUG. I deployed a Workstation 7 Home lab on this Gigabyte motherboard. Though my deployment was simple, I was able deploy ESX 3.5 – 4.x with only 8GB of RAM and attach it to an IOMega ix4-200d. I used it at our Phoenix VMUG meetings to teach others about home labs. I found the receipt for the CPU ($150) and motherboard ($77), wow price sure have changed.

REF Link – Home Lab – Install of ESX 3.5 and 4.0 on Workstation 7

Gen2: 2011-2013 Gigabyte GA-Z68XP-UD3 Workstation 8 | ESXi 4-5

Gen1 worked quite well for what I needed but it was time to expand as my I started working for VMware as a Technical Account Manager. I needed to keep my skills sharp and deploy more complex home lab environments. Though I didn’t know it back then, this was the start of my HOME LABS: A DEFINITIVE GUIDE. I really started to blog about the plan to update and why I was making different choices. I ran into a very unique issues that even Gigabyte or Hitachi could figure out, I blogged about here.

Deployed with an i7-2600 ($300), Gigabyte GA-Z68XP-UD3 ($150), and 16GB DDR3 RAM

REF Link: Update to my Home Lab with VMware Workstation 8 – Part 1 Why

Gen2: Zotac M880G-ITX then the ASRock FM2A85X-ITX | FreeNAS Sever

Back in the day I needed better performance from my shared storage as the IOMega had reached its limits. Enter the short lived FreeNAS server to my home lab. Yes it did preform better but man it was full of bugs and issues. Some due to the Zotac Motherboard and some with FreeNAS. I was happy to be moving on to vSAN with Gen3.

REF: Home Lab – freeNAS build with LIAN LI PC-Q25, and Zotac M880G-ITX

Gen3: 2012-2016 MSI Z68MA-G45 (B3) | ESXi 5-6

I needed to expand my home lab into dedicated hosts. Enter the MSI Z68MA-G45 (B3). It would become my workhorse expanding it from one server with the Gen 2 Workstation to 3 dedicated hosts running vSAN.

REF: VSAN – The Migration from FreeNAS

Gen4: 2016-2019 Gigabyte MX31-BS0 

This mobo was used in my ‘To InfiniBand and beyond’ blog series. It had some “wonkiness” about its firmware updates but other then that it was a solid performer. Deployed with a E3-1500 and 32GB RAM

REF: Home Lab Gen IV – Part I: To InfiniBand and beyond!

Gen 5: 2019-2020 JINGSHA X79

I had maxed out Gen 4 and really needed to expand my CPU cores and RAM. Hence the blog series title – ‘The Quest for More Cores!’. Deployed with 128GB RAM and Xeon E5-2640 v2 8 Cores it fit the bill. This series is where I started YouTube videos and documenting my builds per my design guides. Though this mobo was good for its design its lack of PCIe slots made it short lived.

REF: Home Lab GEN V: The Quest for More Cores! – First Look

Gen 7: 2020-2023: Supermicro X9DRD-7LN4F-JBOD and the MSI PRO Z390-A PRO

Gen 5 motherboard fell short when I wanted to deploy and all flash vSAN based on NVMe. With this Supermicro motherboard I had no issues with IO and deploying it as all Flash vSAN. It also gathered the attention of Intel to which they offered me their Optane drives to create an All Flash Optane system. More on that in Gen 8.

The MSI motherboard was a needed update to my VMware Workstation system. I built it up as a Workstation / Plex server and it did this job quite well.

This generation is when I started to align my Gen#s to vSphere releases. Makes it much easier to track.

REF: Home Lab Generation 7: Updating from Gen 5 to Gen 7

Gen 8: 2023-2024 Dell T7820 VMware Dedicated Hosts

With some support from Intel I was able to uplift my 3 x Dell T7820 workstations into a great home lab. They supplied Engineering Samples CPUs, RAM, and Optane Disks. Plus I was able to coordinate the distribution of Optane disks to vExperts Globally. It was a great homelab and I leaned a ton!

REF: Home Lab Generation 8 Parts List (Part 2)

Gen 8-9: 2023-2026 ASRack Rock EPC621D8A VMware Workstation Motherboard

Evolving my Workstation PC I used this ASRack Rock motherboard. It was the perfect solution for running nested clusters of ESXi VMs with vSAN ESA. It was until most recently a really solid mobo and I even got it to run nested VCF 9 simple install.

REF: Announcing my Generation 8 Super VMware Workstation!

Gen 9: 2024 – Current

As of this date its still under development. See my Home Lab BOM for more information. However, I’m moving my home lab to only nested VCF 9 deployment on Workstation and not dedicated servers.

Windows 11 Workstation VM asking for encryption password that you did not explicitly set

Posted on Updated on

I had created a Windows 11 VM on Workstation 25H2 and then moved it to a new deployment of Workstation. Upon powerup it the VM stated I must supply a password (fig-1) as the VM was encrypted. In this post I’ll cover why this happened and how I got around it.

Note: Disabling TPM/Secure Boot is not  recommended for any system. Additionally, bypassing security leaves systems open for attack. If you are curious around VMware system Hardening check out this great video by Bob Plankers.

(Fig-1)

Why did this happen? As of VMware Workstation 17 encryption is required with a TPM 2.0 device, which is a requirement for Windows 11. When you create a new Windows 11×64 VM, the New VM Wizard (fig-2) asks you to set an encryption password or auto-generated one. This enables the VM to support Windows 11 requirements for TPM/Secure boot.

(Fig-2)

I didn’t set a password, where is the auto-generated password kept? If you allowed VMware to “auto-generate” the password, it is likely stored in your host machine’s credential manager. For Windows, open the Windows Credential Manager (search for “Credential Manager” in the Start Menu). Look for an entry related to VMware, specifically something like “VMware Workstation”.

I don’t have access to the PC where the auto-generated password was kept, how did I get around this? All I did was edit the VMs VMX configuration file commenting out the following. Then added the VM back into Workstation. Note: this will remove the vTPM device from the virtual hardware, not recommended.

# vmx.encryptionType
# encryptedVM.guid
# vtpm.ekCSR
# vtpm.ekCRT
# vtpm.present
# encryption.keySafe
# encryption.data

How could I avoid this going forward? 2 Options

Option 1 – When creating the VM, set and record the password.

Option 2 – To avoid this all together, use Rufus to create a new VM without TPM/Secure boot enabled.

  • Use Rufus to create a bootable USB drive with Windows 11. When prompted choose the options to disable Secure Boot and TPM 2.0.
  • Once the USB is created create a new Windows 11×64 VM in Workstation.
  • For creation options choose Typical > choose I will install the OS later > choose Win11x64 for the OS > chose a name/location > note the encryption password > Finish
  • When the VM is completed, edit its settings > remove the Trusted Platform Module > then go to Options > Access Control > Remove Encryption > put in the password to remove it > OK
  • Now attach the Rufus USB to the VM and boot to it.
  • From there install Windows 11.

Wrapping this up — Bypassing security allowed me to access my VM again. However, it leaves the VM more vulnerable to attack. In the end, I enabled security on this vm and properly recorded its password.

VMware Workstation Gen 9: FAQs

Posted on Updated on

I complied a list of frequently asked questions (FAQs) around my Gen 9 Workstation build. I’ll be updating it from time to time but do feel free to reach out if you have additional questions.

Last Update: 07/20/2026

Why Generation 9? Starting with the Gen 7 build, the Gen Number aligns to the version of vSphere it was designed for. So, Gen 9 = VCF 9. It also helps my readers to track the Generations that interests them the most.

Why are you running Workstation with BOM1 vs. dedicated ESX servers? I wanted to give my readers a different take on how to setup a home lab with Workstation. With Workstation, I can run/deploy multiple types of home labs and do simple backup/recovery, plus Workstation’s snapshot manager allow me to roll back labs quite quickly. I find Workstation very adaptable, and making my lab time about learning rather than maintenance.

Why is BOM2 using nested single ESX servers? In BOM1 I pushed Workstation to its limits and when VCF 9.1 requirements came out it simply could not keep up. I moved my deployment to a single nested ESX host. See the FAQs below for more information.

Where can I find your Bill of Materials for both BOMs? See my Home Lab BOM page.

**BOM1 FAQ**

What topics does the BOM1 VCF 9.0 Series cover? The BOM1 series provides a comprehensive, step-by-step guide for deploying VMware Cloud Foundation (VCF) 9.0.1 in a nested lab environment. The series covers the full lifecycle, including initial planning and requirements (Part 1), the use of templates (Part 2), and setting up essential core network services (Part 3).  Subsequent steps detail the deployment of ESX hosts (Part 4) and configuring the VCF installer with necessary VLAN segmentation (Part 5). To optimize the setup, the guide covers creating an offline repository for VCF components (Part 6), followed by the deployment of VCF 9.0.1 (Part 7).

Finally, the series outlines critical “day-two” operations, such as licensing the environment (Part 8) and managing the proper shutdown and startup procedures for the nested infrastructure (Part 9). This approach creates a fully functional, reproducible lab for testing the latest VMware technologies. For the full series, visit VMExplorer.

Why isn’t Workstation with BOM1 running VCF 9.1? BOM1 worked well with VCF9, however, moving it to VCF 9.1 posed some limitations Workstation could not overcome. Trying to run multiple ESX hosts that are maxed out started to cause some latency and performance delays.

Where can I find your Gen 9 (BOM1 or BOM2) Build series? All of my most popular content, including the Gen 9 BOM builds can be found under Best of VMX.

What version of Workstation are you using with BOM1? Currently, VMware Workstation 26H1, this may change over time see my Home Lab BOM for more details.

How performant is running VCF 9 BOM1 on Workstation? In my testing I’ve had adequate success with a simple VCF install. Clicks through out the various applications didn’t seem to lag. However, when adding more hosts or deploy VCF Automation datastore lags and response time were noticeable.

What core services are needed to support this VCF Deployment? Core Services are supplied via Windows Server. They include AD, DNS, NTP, RAS, and DHCP. DNS, NTP, and RAS being the most important.

What are your goals with Gen 9 BOM1? To develop and build a platform that is able to run the stack of VCF 9 product for Home Lab use. See Gen 9 Part 1 for more information on goals.

What can I run on BOM1 VCF 9.0? I have successfully deployed a simple VCF deployment, but I don’t recommend running VCF Automation on this BOM.

What VCF 9 products are running in BOM1 VCF 9.0? Initial components include: VCSA, VCF Operations, VCF Collector, NSX Manager, Fleet Manager, and SDDC Manager all running on the 3 x Nested ESX Hosts.

Are you running both mobo configurations? No I’m only running the current mobo listed on my Home Lab BOM page.

Do I really need this much hardware? No you don’t. The parts listed on my BOM is just how I did it. I used some parts I had on hand and some I bought used. My recommendation is, use what you have and upgrade when you need to.

What should I do to help with performance? Invest in highspeed disk, CPU cores, and fast RAM. I highly recommend lots of properly deployed NVMe disks for your nested ESX hosts. Make sure you adjust performance in Windows 11.

Note: I highly recommend getting a system with DDR5 RAM and the fastest RAM you can find. When pushing Workstation this far RAM speed is a big factor. DD4 2933Mhz, works but lags under heavy loads.

What do I need for multiple NVMe Drives? If you plan to use multiple NVMe drives into a single PCIe slot you’ll need a motherboard that supports bifurcation OR you’ll need an PCIe NVMe adapter that will support it. Not all NVMe adapters are the same, so do your research before buying.

**BOM2 FAQ**

What are your plans for BOM2? It’s going to be based on nested ESX hosts with VCF 9.1, more to come soon.

VMware Workstation Gen 9: Part 9 Shutting down and starting up the environment

Posted on Updated on

Deploying the VCF 9 environment on to Workstation was a great learning process. However, I use my server for other purposes and rarely run it 24/7. After its initial deployment, my first task is shutting down the environment, backing it up, and then starting it up. In this blog post I’ll document how I accomplish this.

NOTE:

  • License should be completed for a VCF 9 environment first before performing the steps below. If not, the last step, vSAN Shutdown will cause an error. There is a simple work around.
  • I do fully complete each step before moving to the next. Some steps can take some time to complete.

How to shutdown my VCF Environment.

My main reference for VCF 9 Shut down procedures is the VCF 9 Documentation on techdocs.broadcom.com (See REF URLs below). The section on “Shutdown and Startup of VMware Cloud Foundation” is well detailed and I have placed the main URL in the reference URLs below. For my environment I need to focus on shutting down my Management Domains as it also houses my Workload VMs.

Here is the order in which I shutdown my environment. This may change over time as I add other components.

Note – it is advised to complete each step fully before proceeding to the next step.

Shutdown OrderSDDC Component
In vCenter, shutdown all non-essential guest VM’s
1 – Not needed, not deployed yetVCF Automation
2 – Not needed, not deployed yetVCF Operations for Networks
3 – From VCSA234, locate a VCF Operations collector appliance.(opscollectorapplaince)
– Right-click the appliance and select Power > Shut down Guest OS.
– In the confirmation dialog box, click Yes.
– Wait for it to fully power off
VCF Operations collector
4 – Not needed, not deployed yetVCF Operations for logs
5 – Not needed, not deployed yetVCF Identity Broker
6 – From vcsa234, in the VMs and Templates inventory, locate the VCF Operations fleet management appliance (fleetmgmtappliance.nested.local)
– Right-click the VCF Operations fleet management appliance and select Power > Shut down Guest OS.
– In the confirmation dialog box, click Yes.
– Wait for it to fully power off
VCF Operations fleet management
7 – You shut down VCF Operations by first taking the cluster offline and then shutting down the appliances of the VCF Operations cluster.
– Log in to the VCF Operations administration UI at the https://vcfcops.nested.local/admin URL as the admin local user.
– Take the VCF Operations cluster offline. On the System status page, click Take cluster offline.
– In the Take cluster offline dialog box, provide the reason for the shutdown and click OK.
Wait for the Cluster status to read Offline. This operation might take about an hour to complete. (With no data mine took <10 mins)
– Log in to vCenter for the management domain at  https://vcsa234.nested.local/ui as a user with the Administrator role.
– There could be other options for shutting down this appliance. Using Broadcom KB 341964 as a reference, I determined my next step is to simply Right-click the vfccops appliance and select Power > Shut down Guest OS.
– In the VMs and Templates inventory, locate a VCF Operations appliance.
– Right-click the appliance and select Power > Shut down Guest OS.
– In the confirmation dialog box, click Yes.
– This operations takes several minutes to complete.
– Wait for it to fully power off
VCF Operations
8 – Not Needed, not deployed yetVMware Live Site Recovery for the management domain
9 – Not Needed, not deployed yetNSX Edge nodes
10 – I continue shutting down the NSX infrastructure in the management domain and a workload domain by shutting down the one-node NSX Manager by using the vSphere Client.
– Log in to vCenter for the management domain at https://vcsa234.nested.local/ui as a user with the Administrator role.
– Identify the vCenter instance that runs NSX Manager.
– In the VMs and Templates inventory, locate the NSX Manager (nsxmgr.nested.local) appliance.
– Right-click the NSX Manager appliance and select Power > Shut down Guest OS.
– In the confirmation dialog box, click Yes.
– This operation takes several minutes to complete.
– Wait for it to fully power off
NSX Manager
11 – Shut down the SDDC Manager appliance in the management domain by using the vSphere Client.
– Log in to vCenter for the management domain at https://vcsa234.nested.local/ui as a user with the Administrator role.
– In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
– Right-click the SDDC Manager appliance (SDDCMGR108.nested.local) and click Power > Shut down Guest OS.
– In the confirmation dialog box, click Yes.
– This operation takes several minutes to complete.
– Wait for it to fully power off
SDDC Manager
12 – You use the vSAN shutdown cluster wizard in the vSphere Client to shut down gracefully the vSAN clusters in a management domain. The wizard shuts down the vSAN storage and the ESX hosts added to the cluster.
– Identify the cluster that hosts the management vCenter for this management domain.
– This cluster must be shut down last.
– Log in to vCenter for the management domain at https://vcsa234.nested.local/ui as a user with the Administrator role.
– For a vSAN cluster, verify the vSAN health and resynchronization status.
– In the Hosts and Clusters inventory, select the cluster and click the Monitor tab.
– In the left pane, navigate to vSAN Skyline health and verify the status of each vSAN health check category.
– In the left pane, under vSAN Resyncing objects, verify that all synchronization tasks are complete.
– Shut down the vSAN cluster.
– In the inventory, right-click the vSAN cluster and select vSAN > Shutdown cluster.
– In the Shutdown Cluster wizard, verify that all pre-checks are green and click Next.
– Review the vCenter Server notice and click Next.
– Enter a reason for performing the shutdown, and click Shutdown.
– Briefly monitor the progress of the vSAN shutdown in vCenter. Eventually, VCSA will be shutdown and connectivity to it will be lost. I then monitor the shut down of my ESX host in Workstation.
– The shutdown operation is complete after all ESX hosts are stopped.
Shut Down vSAN and the ESX Hosts in the Management Domain

OR

Manually Shut Down and Restart the vSAN Cluster


If vSAN Fails to shutdown due to a license issue, then under the vSAN Cluster > Configure > Services, choose ‘Resume Shutdown’ (Fig-3)

Next the ESX hosts will power off and then I can do a graceful shutdown of my Windows server AD230. In Workstation, simply right click on this VM > Power > Shutdown Guest. Once all Workstation VM’s are powered off, I can run a backup or exit Workstation and power off my server.Power off AD230

(Fig-3)

Backing up my VCF Environment

With my environment fully shut down, now I can start the backup process. See my blog Backing up Workstation VMs with PowerShell for more details.

How to restart my VCF Environment.

Startup OrderSDDC Component
PRE-STEP:
– Power on my Workstation server and start Workstation.
– In Workstation power on my AD230 VM and ensure / verify all the core services (AD, DNS, NTP, and RAS) are working okay.

Start up the VCF Cluster:
1 – One at a time power on each ESX Host.
– vCenter is started automatically. Wait until vCenter is running and the vSphere Client is available again.
– Log in to vCenter at 
https://vcsa234.nested.local/ui as a user with the Administrator role.
– Restart the vSAN cluster. In the Hosts and Clusters inventory, right-click the vSAN cluster and select vSAN Restart cluster.
– In the Restart Cluster dialog box, click Restart.
– Choose the vSAN cluster > Configure > vSAN > Services to see the vSAN Services page. This will display information about the restart process.
– After the cluster has been restarted, check the vSAN health service and resynchronization status, and resolve any outstanding issues. Select the cluster and click the Monitor tab.
– In the left pane, under vSAN > Resyncing objects, verify that all synchronization tasks are complete.
– In the left pane, navigate to vSAN Skyline health and verify the status of each vSAN health check category.
Start vSAN and the ESX Hosts in the Management DomainStart ESX Hosts with NFS or Fibre Channel Storage in the Management Domain
2 – From vcsa234 locate the sddcmgr108 appliance.
– In the VMs and templates inventory, Right Click on the SDDC Manager appliance > Power > Power On.
– Wait for this vm to boot. Check it by going to https://sddcmgr108.nested.local
– As its getting ready you may see “VMware Cloud Foundation is initializing…”
– Eventually you’ll be prompted by the SDDC Manager page.
– Exit this page.
SDDC Manager
3 – From the VCSA234 locate the nsxmgr VM
then Right-click, select Power > Power on.
– This operation takes several minutes to complete until the NSX Manager cluster becomes fully operational again and its user interface – accessible.
– Log in to NSX Manager for the management domain at https://nsxmgr.nested.local as admin.
– Verify the system status of NSX Manager cluster.
– On the main navigation bar, click System.
– In the left pane, navigate to Configuration > Appliances.
– On the Appliances page, verify that the NSX Manager cluster has a Stable status and all NSX Manager nodes are available.

Notes — Give it time.
– You may see the Cluster status go from Unavailable > Degraded, ultimately you want it to show Available.
– In the Node under Service Status you can click on the # next to Degraded. This will pop up the Appliance details and will show you which item are degraded.
– If you click on Alarms, you can see which alarms might need addressed
NSX Manager
4 – Not Needed, not deployed yetNSX Edge
5 – Not Needed, not deployed yetVMware Live Site Recovery
6 – From vcsa234, locate vcfops.nested.lcoal appliance.
– Following the order described in Broadcom KB 341964.
– For my environment I simply Right-click on the appliance and select Power > Power On.
– Log in to the VCF Operations administration UI at the https://vcfops.nested.lcoal/admin URL as the admin local user.
– You may see ‘Retrieving Cluster Status’ , give it time. Mine took about <2mins
– On the System status page, Under Cluster Status, click Bring Cluster Online.
– You may see ‘Retrieving Cluster Status’ , give it time. Mine took about <2mins

Notes — Give it time.
This operation might take about an hour to complete.
– Took <15 mins to come Online
– Cluster Status update may read: ‘Going Online’
– To the right of the node name, all of the other columns continue to update, eventually showing ‘Running’ and ‘Online’
– Cluster Status will eventually go to ‘Online’
VCF Operations
7 – From vcsa234 locate the VCF Operations fleet management appliance (fleetmgmtappliance.nested.local)
Right-click the VCF Operations fleet management appliance and select Power > Power On.
– In the confirmation dialog box, click Yes.
– Allow it to boot

Note –
Direct access to VCF Ops Fleet Management appliance is disabled. Go to VCF Operations > Fleet Mgmt > Lifecycle > VCF Management for appliance management.
VCF Operations fleet management
8 – Not Needed, not deployed yetVCF Identity Broker
9 – Not Needed, not deployed yetVCF Operations for logs
10 – From vcsa234, locate a VCF Operations collector appliance. (opscollectorappliance)
Right-click the VCF Operations collector appliance and select Power > Power On.
In the configuration dialog box, click Yes.
VCF Operations collector
11 – Not Needed, not deployed yetVCF Operations for Networks
12 – Not Needed, not deployed yetVCF Automation

REF: