VMware VS4-ENT-PL-A Setup Guide - Page 263

Enable Lockdown Mode Using the Direct Console, Under System, select

Page 263 highlights

Chapter 8 Setting Up ESXi Enable Lockdown Mode Using the Direct Console To increase the security of your ESXi hosts, you can put them in lockdown mode. When you enable lockdown mode, no users other than vpxuser have authentication permissions, nor can they perform operations against the host directly. Lockdown mode forces all operations to be performed through vCenter Server. When a host is in lockdown mode, you cannot run vSphere CLI commands from an administration server, from a script, or from vMA against the host. External software or management tools might not be able to retrieve or modify information from the ESXi host. NOTE Users with the DCUI Access privilege are authorized to log in to the Direct Console User Interface (DCUI) when lockdown mode is enabled. When you disable lockdown mode using the DCUI, all users with the DCUI Access privilege are granted the Administrator role on the host. You grant the DCUI Access privilege in Advanced Settings. Enabling or disabling lockdown mode affects which types of users are authorized to access host services, but it does not affect the availability of those services. In other words, if the ESXi Shell, SSH, or Direct Console User Interface (DCUI) services are enabled, they will continue to run whether or not the host is in lockdown mode. You can enable lockdown mode using the Add Host wizard to add a host to vCenter Server, using the vSphere Web Client to manage a host, or using the direct console user interface. NOTE If you enable or disable lockdown mode using the Direct Console User Interface (DCUI), permissions for users and groups on the host are discarded. To preserve these permissions, you must enable and disable lockdown mode using the vSphere Web Client connected to vCenter Server. Lockdown mode is available only on ESXi hosts that you add to vCenter Server. See the vSphere Security documentation for more information about lockdown mode. Procedure 1 In the direct console, select Configure Lockdown Mode and press Enter. 2 Press the spacebar to select Enable Lockdown Mode and press Enter. 3 Press Enter. The host is in lockdown mode. Enable Lockdown Mode Using the vSphere Web Client Enable lockdown mode to require that all configuration changes go through vCenter Server. You can also enable or disable lockdown mode through the Direct Console User Interface (DCUI). Procedure 1 Browse to the host in the vSphere Web Client inventory. 2 Click the Manage tab and click Settings. 3 Under System, select Security Profile. 4 In the Lockdown Mode panel, click Edit. 5 Select Enable Lockdown Mode. 6 Click OK. VMware, Inc. 263

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

Enable Lockdown Mode Using the Direct Console
To increase the security of your ESXi hosts, you can put them in lockdown mode.
When you enable lockdown mode, no users other than
vpxuser
have authentication permissions, nor can
they perform operations against the host directly. Lockdown mode forces all operations to be performed
through vCenter Server.
When a host is in lockdown mode, you cannot run vSphere CLI commands from an administration server,
from a script, or from vMA against the host. External software or management tools might not be able to
retrieve or modify information from the ESXi host.
N
OTE
Users with the DCUI Access privilege are authorized to log in to the Direct Console User Interface
(DCUI) when lockdown mode is enabled. When you disable lockdown mode using the DCUI, all users with
the DCUI Access privilege are granted the Administrator role on the host. You grant the DCUI Access
privilege in Advanced Settings.
Enabling or disabling lockdown mode affects which types of users are authorized to access host services,
but it does not affect the availability of those services. In other words, if the ESXi Shell, SSH, or Direct
Console User Interface (DCUI) services are enabled, they will continue to run whether or not the host is in
lockdown mode.
You can enable lockdown mode using the Add Host wizard to add a host to vCenter Server, using the
vSphere Web Client to manage a host, or using the direct console user interface.
N
OTE
If you enable or disable lockdown mode using the Direct Console User Interface (DCUI), permissions
for users and groups on the host are discarded. To preserve these permissions, you must enable and disable
lockdown mode using the vSphere Web Client connected to vCenter Server.
Lockdown mode is available only on ESXi hosts that you add to vCenter Server.
See the
vSphere Security
documentation for more information about lockdown mode.
Procedure
1
In the direct console, select
Configure Lockdown Mode
and press Enter.
2
Press the spacebar to select
Enable Lockdown Mode
and press Enter.
3
Press Enter.
The host is in lockdown mode.
Enable Lockdown Mode Using the vSphere Web Client
Enable lockdown mode to require that all configuration changes go through vCenter Server. You can also
enable or disable lockdown mode through the Direct Console User Interface (DCUI).
Procedure
1
Browse to the host in the vSphere Web Client inventory.
2
Click the
Manage
tab and click
Settings
.
3
Under System, select
Security Profile
.
4
In the Lockdown Mode panel, click
Edit
.
5
Select
Enable Lockdown Mode
.
6
Click
OK
.
Chapter 8 Setting Up ESXi
VMware, Inc.
263