The vSphere client could not connect to "x.x.x.x" You do not have permission...

Full error is The vSphere client could not connect to "x.x.x.x". You do not have permission to login to the server 'x.x.x.x."

This error just started happening this week.  We're running ESX 5 and I've restarted the server a number of times.  Both the domain admin and local accounts I've tried return the same error.  All VMware services are running and I can RDP into the Vsphere server without issue.
LVL 1
First LastAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

IanThCommented:
so it sounds like a network problem can you tell me your setup can you login to the host via vclient root password if you can check the server is ok in the esxi host
0
First LastAuthor Commented:
We're running ESX 5 with three Dell R710s as hosts.  I can access all three hosts directly with the vsphere client and root password.  I can RDP into the vcenter server, all services are up and running.  There are no errors in the event log that seem relevant...its a tough one!
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
the IP address you are connecting to is the ESXi server?

can you connect with IP address via ssh, web browser?
0
Acronis True Image 2019 just released!

Create a reliable backup. Make sure you always have dependable copies of your data so you can restore your entire system or individual files.

IanThCommented:
where is your dc ?
0
First LastAuthor Commented:
There are two DCs on the same subnet, both are up and available, pings return fine.
0
First LastAuthor Commented:
@hanccocka - I am attempting to use my vsphere client to connect to the vcenter server to manage our ESX 5.1 environment.  Its worked fine until this past weekend.  I can RDP into the vcenter server and I can access each of the three hosts directly with the vsphere client and root password.
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
ssh to the IP address, can you do this, and confirm this is the correct IP address?
0
IanThCommented:
so your can your dc ping the hosts ?
0
First LastAuthor Commented:
@hanccocka - I can SSH to the hosts individually but not the vcenter server (which I think is correct)

@IanTh - there are no communications problems between the vcenter server and the DCs, I can ping in both directions, there are no firewalls between them, and all services are running on all servers
0
coolsport00Commented:
Can you connect to the Host directly your vCenter VM is on (assuming your vCenter is a VM) with vSphere Client, open console & log on to your vCenter guest, use vSphere Client within your vCenter VM and try and log on to vCenter there? Check the permissions if you can log on. Since vCenter uses the same Admin permissions that are local guest OS Admin on the vCenter VM, check those permissions.

~coolsport00
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
is the issue connecting to esxi server or vcenter server?
0
coolsport00Commented:
@hanccocka - he mentioned earlier he could log onto each Host, just not vCenter
0
First LastAuthor Commented:
@coolsport00 - I'll try that now

@hanccocka - I am trying to connect my vsphere client to the vcenter server
0
coolsport00Commented:
Ok, let us know what happens. And again, check the local Administrators group on your vCenter VM. And that's assuming you've given a group in your AD local admin rights (well, Domain Admin gets local Admin by default)...

~coolsport00
0
First LastAuthor Commented:
I tried running the client on the vcenter server but ran into the exact same problem.  Permissions are set the same as always with domain admins having local admin rights to the server and I'm using one to test with today.  Same behavior using the web client.
0
coolsport00Commented:
Can you log on with the vCenter local admin acct?
0
First LastAuthor Commented:
No, I get a different error there though:

Cannot complete logon due to an incorrect username or password

I'm confident I have the right credentials.  I can log into each of the three physical hosts individually with the same ID no problem.
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
are you ESXi hosts AD integrated, because usually IDs would be different? eg root for ESXi
0
First LastAuthor Commented:
I can only log directly into the hosts using the root ID/password, AD authentication only works when I log into vcenter (which I can't do at the moment).
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
is your Loca Admin group in the VCenter config?

add a local admin account to your vCenter Server.
0
First LastAuthor Commented:
Yes, local admin group is in the Vcenter config.  I added another local admin account but get the same error.
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
any events in event log on Windows OS?

check vCenter logs
0
First LastAuthor Commented:
The only event log details even close to relevant has to do with vmtools:

Event ID 1000
[ warning] [vmusr:vmusr] vmware::tools::UnityPBRPCServer::Start: Failed to register with the host!

and under the same Event ID
[ warning] [vmsvc:powerops] Unable to send the status RPC.

I'm gathering the vcenter logs now.  I did find something interesting looking at the Active Directory Web Services log:

Event ID 1209
Active Directory Web Services encountered an error while reading the settings for the specified Active Directory Lightweight Directory Services instance.  Active Directory Web Services will retry this operation periodically.  In the mean time, this instance will be ignored.
 Instance name: ADAM_VMwareVCMSDS

Now that looks relevant.  If it can't do LDAP lookups then authentication would fail which is exactly the error I'm getting.  Not sure what the error indicates though, I'm researching now.  If you've seen it before let me know!
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
okay, if ADAM is broken this is certainly the issue.
0
First LastAuthor Commented:
0
First LastAuthor Commented:
Ok, no dice.  The error is gone from the event log now but I'm still getting the same exact logon error when starting up the vsphere client.
0
First LastAuthor Commented:
Sorry, I take that back...was looking at the wrong log.  I'm still seeing the same errors in the Active Directory Web Services event log even after the registry change.
0
First LastAuthor Commented:
Anyone?
0
First LastAuthor Commented:
This wound up being a problem with the host VMs on 5.1 and vcenter on 5.0.  Upgrading vcenter fixed the issue.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
This error just started happening this week.  

I'm surprised it worked the week before!

VC 5.0 is not compatible with ESXi 5.1.
0
First LastAuthor Commented:
Yeah, that's the only thing I don't understand.  It actually ran for a week or two before it quit working.
0
coolsport00Commented:
Glad you figured it out and good you didn't delete this question....could help others in the future :)

Regards.
~coolsport00
0
First LastAuthor Commented:
Answered own question
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VMware

From novice to tech pro — start learning today.