Solved

lockdown mode / DCIU

Posted on 2013-12-03
5
495 Views
Last Modified: 2013-12-05
can enforcing lockdown mode /disabling DCUI create any support type issues? I.e. are there any cases whereby you may wish to perform troubleshooting directly on the host as opposed to using vCenter?

And secondly is it an easy thing to enable/disable - or quite a time consuming excercise? I was thinking it could be enabled (ld mode) by default and temporarily disabled if theres a genuine business case/then re-enabled after the work is done?
0
Comment
Question by:pma111
  • 3
  • 2
5 Comments
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39692709
1. Yes it can cause issues, if you visit the console, to perform additional diagnostics, and the console is locked, you will not be able to access the server.

A bit like if there is no keyboard attached!

2. It is easy to enable and disable from vSphere vCenter Server.

VMware KB: Enabling or disabling Lockdown mode on an ESXi host
0
 
LVL 3

Author Comment

by:pma111
ID: 39692718
So is that the appraoch you follow, enable LD mode by default, disable as and when neccesary?
0
 
LVL 119
ID: 39692724
If you believe you may have a security risk in your computer room or datacentre.

We see it enable, when you have servers in a shared datacentre location with many other companies servers.
0
 
LVL 3

Author Comment

by:pma111
ID: 39692736
But it would also save the impact if someone gained unauthorised access to the server room, i.e. break in? i,e,.defence in depth strategy, or are you pretty much toast if someone breaks in anyway?
0
 
LVL 119
ID: 39692741
If someone broke in, they could remove the server!

and deal with access to the server later. (easily!)
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If your vDisk VHD file gets deleted from the image store accidentally or on purpose, you won't be able to remove the vDisk from the PVS console. There is a known workaround that is solid.
HOW TO: Install and Configure VMware vSphere Hypervisor 6.5 (ESXi 6.5), Step by Step Tutorial with screenshots. From Download, Checking Media, to Completed Installation.
Teach the user how to rename, unmount, delete and upgrade VMFS datastores. Open vSphere Web Client: Rename VMFS and NFS datastores: Upgrade VMFS-3 volume to VMFS-5: Unmount VMFS datastore: Delete a VMFS datastore:
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question