Solved

lockdown mode / DCIU

Posted on 2013-12-03
5
504 Views
Last Modified: 2013-12-05
can enforcing lockdown mode /disabling DCUI create any support type issues? I.e. are there any cases whereby you may wish to perform troubleshooting directly on the host as opposed to using vCenter?

And secondly is it an easy thing to enable/disable - or quite a time consuming excercise? I was thinking it could be enabled (ld mode) by default and temporarily disabled if theres a genuine business case/then re-enabled after the work is done?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 121

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39692709
1. Yes it can cause issues, if you visit the console, to perform additional diagnostics, and the console is locked, you will not be able to access the server.

A bit like if there is no keyboard attached!

2. It is easy to enable and disable from vSphere vCenter Server.

VMware KB: Enabling or disabling Lockdown mode on an ESXi host
0
 
LVL 3

Author Comment

by:pma111
ID: 39692718
So is that the appraoch you follow, enable LD mode by default, disable as and when neccesary?
0
 
LVL 121
ID: 39692724
If you believe you may have a security risk in your computer room or datacentre.

We see it enable, when you have servers in a shared datacentre location with many other companies servers.
0
 
LVL 3

Author Comment

by:pma111
ID: 39692736
But it would also save the impact if someone gained unauthorised access to the server room, i.e. break in? i,e,.defence in depth strategy, or are you pretty much toast if someone breaks in anyway?
0
 
LVL 121
ID: 39692741
If someone broke in, they could remove the server!

and deal with access to the server later. (easily!)
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
What if you have to shut down the entire Citrix infrastructure for hardware maintenance, software upgrades or "the unknown"? I developed this plan for "the unknown" and hope that it helps you as well. This article explains how to properly shut down …
Teach the user how to use configure the vCenter Server storage filters Open vSphere Web Client:  Navigate to vCenter Server Advanced Settings: Add the four vCenter Server storage filters: Review the advanced settings: Modify the values of the four v…
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question