Advice: copy files to/from DMZ

8 views
Skip to first unread message

Mike Leone

unread,
Mar 25, 2026, 12:54:17 PM (7 days ago) Mar 25
to NTSysAdmin, NTPowershell Mailing List
I want to hear from you guys about this. We used to use VMware, and so copying/pasting files (such as certificate requests) was easy, using the VMware powershell cmdlets. (we don't allow RDP into the DMZ, not even from the trusted LAN).

Now, however, we are using Nutanix as a hypervisor. And they have no such cmdlets ... they do have a remote control (just as VMware does), but the Nutanix remote control does not allow you to copy and paste. 

This makes copying files somewhat problematical. Oh, it's easy enough to get files ONTO the VM - we just put'em in an ISO, mount it on the VM, and copy them out. But there's no easy way to copy a file FROM the VM ...

I considered a Powershell remote session, maybe. Establish the remote session into the trusted LAN, do a copy-item -ToSession, that should get the file off there (presuming I know where on the remote VM it is, in the first place, obviously

(I wish we allowed SSH access, I could do a WinSCP. But we don't allow that on all the VMs on the DMZ, only some of them.

So what do you do? Or how would you handle this situtaon? As I said, getting files ONTO the VM is easy. Getting files OFF the VM (unless we change things, like setting up and allowing SSH so I can SCP) seems a lot more difficult. (and yes, I know it's *supposed* to be difficult).

Thanks
--

Mike. Leone, <mailto:tur...@mike-leone.com>

PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <http://www.flickr.com/photos/mikeleonephotos>

Wright, John M

unread,
Mar 25, 2026, 1:20:46 PM (7 days ago) Mar 25
to ntpowe...@googlegroups.com, NTSysAdmin

It looks like Nutanix has something for Powershell, though I’ve never used it.  The link below links in turn to the Cmdlets reference.  That page has links to download/install guide.

 

https://www.nutanixbible.com/19c-powershell.html

 

--

John Wright

IT Support Specialist

1800 Old Bluegrass Avenue, Louisville, KY 40215

502.708.9953

Please submit IT requests to Hazelwoo...@bluegrass.org

24 Hour Helpline 1.800.928.8000

  

CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.

 

From: ntpowe...@googlegroups.com <ntpowe...@googlegroups.com> On Behalf Of Mike Leone
Sent: Wednesday, March 25, 2026 12:54 PM
To: NTSysAdmin <ntsys...@googlegroups.com>; NTPowershell Mailing List <ntpowe...@googlegroups.com>
Subject: [ntpowershell] Advice: copy files to/from DMZ

 

EXTERNAL EMAIL - This email was sent by a person from outside your organization. Exercise caution when clicking links, opening attachments or taking further action, before validating its authenticity.

--
You received this message because you are subscribed to the Google Groups "ntpowershell" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntpowershell...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntpowershell/CAHBr%2B%2Bjh1_gEjWRraKjhVo-EWQ7sE80VFsrLSLjsktyHGZBKpg%40mail.gmail.com.

Mike Leone

unread,
Mar 25, 2026, 2:14:25 PM (7 days ago) Mar 25
to ntpowe...@googlegroups.com, NTSysAdmin
On Wed, Mar 25, 2026 at 1:20 PM Wright, John M <John....@newvista.org> wrote:

It looks like Nutanix has something for Powershell, though I’ve never used it.  The link below links in turn to the Cmdlets reference.  That page has links to download/install guide.

 

https://www.nutanixbible.com/19c-powershell.html


There are 2 sets of CMDLETs - v1 and v2 (which requires PS v7 ... well, technically it says PS 6, but you get the point).

And there are CMDLETs in v1 that are not in v2, and vice versa. 
And none of them are the equivalent of a copy (VMware PowerCLI has "Copy-VMGeustFile" and you specify "-ToLocal" or "-ToGuest", depending on which direction you're copying).

No such equivalent for Nutanix, unfortunately.

Mike Leone

unread,
Mar 25, 2026, 2:22:41 PM (7 days ago) Mar 25
to ntsys...@googlegroups.com, ntpowe...@googlegroups.com


On Wed, Mar 25, 2026 at 1:24 PM Philip Elder <Phili...@mpecsinc.ca> wrote:

For restrictive environments we use a .VHDX file called something like “Temp_64GB.VHDX”.

 

We drop what we need in-guest onto it, mount it, copy off, and same back.

 

It works.

 

Cludgey, but it works.



I dunno if that type of thing works in Nutanix, I haven't seen any "attach/detach VHDX disk" in the VM config ...

There is an "Add new disk" (obviously), but the only options are to either allocate as new local disk, or clone iitfrom an image ...

image.png

I don't see a way to then take a disk from that VM, and mount it to another VM (unless it's to somehow clone it into their Image Service, which is where we put ISOs ....


 

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

MPECS Inc.

E-mail: Phili...@MPECSInc.Ca

Phone: +1 (780) 458-2028

Web: www.MPECSInc.Com

Blog: Blog.MPECSInc.Com  

Twitter: Twitter.com/MPECSInc

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

 

From: ntpowe...@googlegroups.com <ntpowe...@googlegroups.com> On Behalf Of Mike Leone
Sent: Wednesday, March 25, 2026 10:54
To: NTSysAdmin <ntsys...@googlegroups.com>; NTPowershell Mailing List <ntpowe...@googlegroups.com>
Subject: [ntpowershell] Advice: copy files to/from DMZ

 

I want to hear from you guys about this. We used to use VMware, and so copying/pasting files (such as certificate requests) was easy, using the VMware powershell cmdlets. (we don't allow RDP into the DMZ, not even from the trusted LAN).

--

You received this message because you are subscribed to the Google Groups "ntpowershell" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntpowershell...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntpowershell/CAHBr%2B%2Bjh1_gEjWRraKjhVo-EWQ7sE80VFsrLSLjsktyHGZBKpg%40mail.gmail.com.

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/dd9117814d664efdb90ec8b2572f68b1%40MPECSInc.Ca.

Mike Leone

unread,
Mar 25, 2026, 2:31:07 PM (7 days ago) Mar 25
to ntsys...@googlegroups.com, ntpowe...@googlegroups.com
It's easy enough to do, if we open SSH in the firewall between DMZ and trusted LAN (not DMZ and outside world):

scp user@DMZ-Host:/file/on/DMZ/stuff.txt \Local\path\to\stick\DMZ\files\into\stuff.txt

You just gotta know where on the remote host the files is located, but that's easy enough, using VM remote control (like having to copy off a log file for analysis or something).

And the transaction would be encrypted, at least.

(and make sure SSH is installed on the hosts in the DMZ, of course, which isn't that hard to do, either).




On Wed, Mar 25, 2026 at 1:24 PM Philip Elder <Phili...@mpecsinc.ca> wrote:

For restrictive environments we use a .VHDX file called something like “Temp_64GB.VHDX”.

 

We drop what we need in-guest onto it, mount it, copy off, and same back.

 

It works.

 

Cludgey, but it works.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

MPECS Inc.

E-mail: Phili...@MPECSInc.Ca

Phone: +1 (780) 458-2028

Web: www.MPECSInc.Com

Blog: Blog.MPECSInc.Com  

Twitter: Twitter.com/MPECSInc

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

 

 

From: ntpowe...@googlegroups.com <ntpowe...@googlegroups.com> On Behalf Of Mike Leone
Sent: Wednesday, March 25, 2026 10:54
To: NTSysAdmin <ntsys...@googlegroups.com>; NTPowershell Mailing List <ntpowe...@googlegroups.com>
Subject: [ntpowershell] Advice: copy files to/from DMZ

 

I want to hear from you guys about this. We used to use VMware, and so copying/pasting files (such as certificate requests) was easy, using the VMware powershell cmdlets. (we don't allow RDP into the DMZ, not even from the trusted LAN).

--

You received this message because you are subscribed to the Google Groups "ntpowershell" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntpowershell...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntpowershell/CAHBr%2B%2Bjh1_gEjWRraKjhVo-EWQ7sE80VFsrLSLjsktyHGZBKpg%40mail.gmail.com.

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/dd9117814d664efdb90ec8b2572f68b1%40MPECSInc.Ca.
Reply all
Reply to author
Forward
0 new messages