> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning VMware

> Capturing ESXi hosts and vCenter through their web API—with hosts, virtual machines and switches.

The *VMware* scan module reads ESXi hosts and vCenter through their web API. It
requires a connected [gateway](/docs/en/scan/gateway-install).

## Captured data

The scan creates assets of these types:

| Type | Groups |
| - | - |
| *VMware* | vCenter Details (Tags, Warnings), Links (Datacenter, Hosts, Virtual Machines, Folder Structure, Networks, Datastores, Clusters, Resource Pools, Virtual Switches, Distributed Switches) |
| *VMware Host* | Host Details (System Information, CPU Details, HBA Details, NIC Details, Network Infrastructure), Links (Attached Datastores, Hosted VMs, Assigned Warnings, Resource Pools, Virtual Switches, Distributed Switches) |
| *VMware VM* | Virtualized Hardware (Disk Details, Partition Details, Network Details, Floppy Details, DVD/CD Details), VM Details (VM State, Tools State, HW Information, HA Settings, Snapshot Details, Warnings, Infrastructure Information, Annotations) |
| *VMware vSwitch* | Virtual Switch Details (Configuration Details, Port Group Details), Links (Host Overview, Host Details NICs, Connected VMs) |
| *VMware Distributed vSwitch* | Details (Configuration Details, dvPort Group Details), Links (Assigned VMs, Assigned Hosts) |

How the detail pages of the types are structured is described in
[Virtualization](/docs/en/assets/virtualization).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries the columns *IP/Hostname* and *Credentials*. *IP/Hostname*
takes one ESXi host or one vCenter per row, as an address or hostname.

The *Credentials* column must be filled, with an entry of the type
*User Account*. ESXi and vCenter do not accept a sign-in through the gateway's
service account. An entry in *Credentials for all targets* applies to every row
without an assignment of its own.

## Prerequisites

The scan connects over HTTPS to the web API of the ESXi hosts and the vCenter.

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| HTTPS | 443 | TCP |

### Permissions

* The account is a member of the ReadOnly role.

### Network requirements

* The firewall allows the port.
* If a proxy sits in between, it may need exceptions.

## Common issues

| Symptom | Cause | Resolution |
| - | - | - |
| No connection to the ESXi host or vCenter. | The web API is not reachable or not enabled, or a proxy sits in between. | Test the web API in a browser (`https://<vCenter>/mob`), enable it, and set proxy exceptions if needed. |

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). The ports of all scan modules
are in the [Scan Reference](/docs/en/scan/reference#ports-and-protocols).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.