Stone Computers Knowledgebase

Should I enable Lockdown Mode on my VMWare ESXi Hosts?

Article ID: 109
Last updated: 13 Feb, 2016
Article ID: 109
Last updated: 13 Feb, 2016
Revision: 1
Views: 931
Posted: 09 Jul, 2013
by Andrew Sharrad
Updated: 13 Feb, 2016
by Andrew Sharrad

Lock Down Mode

 

  • When adding Hosts to a VCenter Server, the option is presented to Enable Lock Down mode
  • After a Host has been added to a VCenter Server, the Lock Down mode can be Enabled.

 

Lock down mode confines that Host to be managed by that VCenter server only. Connections using a direct VSphere client will not be possible.

The Risks of Using Lockdown mode

If your VCenter server becomes unavailable, you may not be able to manage Host operations if lock down mode is enabled. We do not recommend enabling lock down mode unless an extreme security risk requires it. Instead, it is better to seperate Host management traffic to a different VLAN and/or subnet. Always use secure root passwords for your hosts and a secure administrator password for your VCenter server.

Reminder: Stone Professional Services (SPS) offer a range of services to help you manage and improve your network. Talk to one of our specialists today so that we can help you build a secure infrastructure.

 

Applies to:

  • Stone server products running VMWare VCenter server

This article was:  
Article ID: 109
Last updated: 13 Feb, 2016
Revision: 1
Views: 931
Posted: 09 Jul, 2013 by Andrew Sharrad
Updated: 13 Feb, 2016 by Andrew Sharrad