Skip to main content
NetApp Knowledge Base

VMware ESXI cannot power on VM, create new VM, or revert snapshots after Native Fpolicy was enabled in System Manager

Views:
2,613
Visibility:
Public
Votes:
2
Category:
ontap-9
Specialty:
NAS
Last Updated:
2/24/2025, 12:52:04 PM

Applies to

  • VMware ESXI
  • NFS
  • Native Fpolicy

Issue

  • VMware ESXI tries to power on VM, but fails with error

Example:

Task      Power On virtual machine
Target    MASTER-Template.726
Status    An error occurred while opening configuration file "/vmfs/volumes/1234-5678/MASTER-Template.726/MASTER-Template.726.vmx": Insufficient permission to access the file.

  • Currently running VMs are not impacted
  • Powered off VMs cannot power on
  • Reverting VM snapshots may also fail with similar permissions issues
  • Packet trace indicates CREATE fails with NFS3ERR_ACCES for file extensions vmx~, and tmp

Example:

79572 2024-07-08 17:12:57.231332 0.000036  10.x.x.x 10.x.x.​​​​​​x NFS 246 5 V3 CREATE Call (Reply In 79574), DH: 0x76c31fa7/Win10-002.vmx~ Mode: UNCHECKED
79574 2024-07-08 17:12:57.231452 0.000063  10.x.x.x 10.x.x.x NFS 106 5 V3 CREATE Reply (Call In 79572) Error: NFS3ERR_ACCES

79638 2024-07-08 17:12:57.238400 0.000043  10.x.x.x 10.x.x.​​​​​​x NFS 254 5 V3 CREATE Call (Reply In 79641), DH: 0x76c31fa7/​​​​Win10-002-aux.xml.tmp Mode: UNCHECKED
79641 2024-07-08 17:12:57.238523 0.000098  10.x.x.x 10.x.x.x NFS 106 5 V3 CREATE Reply (Call In 79638) Error: NFS3ERR_ACCES
  • sectrace -trace-allow yes confirms access is allowed

Example:

Node            Index Filter Details             Reason
--------------- ----- -------------------------- ------------------------------
node01          4     Security Style: UNIX       Access is allowed because the
                      permissions                user has UNIX root privileges
                                                 while reading the file.
                                                 Access is granted for: "Read"
                      Protocol: nfs
                      Volume: vol01
                      Share: -
                      Path: /MASTER-Template
                      .726/MASTER-Template
                      .726.vmx
                      Win-User: -
                      UNIX-User: 0
                      Session-ID: -
snetapp03-a1    4     Security Style: UNIX       Access is allowed because the
                      permissions                user has UNIX root privileges
                                                 while creating the file.
                                                 Access is granted for: "Write"
                      Protocol: nfs
                      Volume: vol01
                      Share: -
                      Path: /MASTER-Template
                      .726/MASTER-Template
                      .726.vmx.lck
                      Win-User: -
                      UNIX-User: 0
                      Session-ID: -

 

 

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.