Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

lockdown mode / DCIU

Posted on 2013-12-03
5
Medium Priority
?
528 Views
Last Modified: 2013-12-05
can enforcing lockdown mode /disabling DCUI create any support type issues? I.e. are there any cases whereby you may wish to perform troubleshooting directly on the host as opposed to using vCenter?

And secondly is it an easy thing to enable/disable - or quite a time consuming excercise? I was thinking it could be enabled (ld mode) by default and temporarily disabled if theres a genuine business case/then re-enabled after the work is done?
0
Comment
Question by:pma111
  • 3
  • 2
5 Comments
 
LVL 125

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 39692709
1. Yes it can cause issues, if you visit the console, to perform additional diagnostics, and the console is locked, you will not be able to access the server.

A bit like if there is no keyboard attached!

2. It is easy to enable and disable from vSphere vCenter Server.

VMware KB: Enabling or disabling Lockdown mode on an ESXi host
0
 
LVL 3

Author Comment

by:pma111
ID: 39692718
So is that the appraoch you follow, enable LD mode by default, disable as and when neccesary?
0
 
LVL 125
ID: 39692724
If you believe you may have a security risk in your computer room or datacentre.

We see it enable, when you have servers in a shared datacentre location with many other companies servers.
0
 
LVL 3

Author Comment

by:pma111
ID: 39692736
But it would also save the impact if someone gained unauthorised access to the server room, i.e. break in? i,e,.defence in depth strategy, or are you pretty much toast if someone breaks in anyway?
0
 
LVL 125
ID: 39692741
If someone broke in, they could remove the server!

and deal with access to the server later. (easily!)
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your vDisk VHD file gets deleted from the image store accidentally or on purpose, you won't be able to remove the vDisk from the PVS console. There is a known workaround that is solid.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Teach the user how to use create log bundles for vCenter Server or ESXi hosts Open vSphere Web Client: Generate vCenter Server and ESXi host log bundle:  Open vCenter Server Appliance Web Management interface and generate log bundle: Open vCenter Se…
This video shows you how to use a vSphere client to connect to your ESX host as the root user. Demonstrates the basic connection of bypassing certification set up. Demonstrates how to access the traditional view to begin managing your virtual mac…
Suggested Courses

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question