6.0

Table Of Contents
Procedure
1 Select the host in the inventory and click the Configuration tab.
2 Under Software, select Advanced Settings.
3 In the left panel, select UserVars.
4 In the UserVars.ESXiShellTimeOut field, enter the availability timeout setting.
You must restart the SSH service and the ESXi Shell service for the timeout to take effect.
5 Click OK.
If you are logged in when the timeout period elapses, your session will persist. However, after you log out
or your session is terminated, users are not allowed to log in.
Create a Timeout for Idle ESXi Shell Sessions
If a user enables the ESXi Shell on a host, but forgets to log out of the session, the idle session remains
connected indefinitely. The open connection can increase the potential for someone to gain privileged access
to the host. You can prevent this by setting a timeout for idle sessions.
The idle timeout is the amount of time that can elapse before the user is logged out of an idle interactive
sessions. Changes to the idle timeout apply the next time a user logs in to the ESXi Shell and do not affect
existing sessions.
Procedure
1 Select the host in the inventory and click the Configuration tab.
2 Under Software, select Advanced Settings.
3 In the left panel, select UserVars.
4 In the UserVars.ESXiShellInteractiveTimeOut field, enter the availability timeout setting.
You must restart the SSH service and the ESXi Shell service for the timeout to take effect.
5 Click OK.
If you are logged in when the timeout period elapses, your session will persist. However, after you log out
or your session is terminated, users are not allowed to log in.
Enable Lockdown Mode in the vSphere Client
Enable lockdown mode to require that all configuration changes go through vCenter Server. You can also
enable or disable lockdown mode through the direct console user interface.
Prerequisites
n
Open a vSphere Client session to a vCenter Server system.
Procedure
1 Select the host in the inventory panel.
2 Click the Configuration tab and click Security Profile.
3 Click the Edit link next to lockdown mode.
The Lockdown Mode dialog box appears.
4 Select Enable Lockdown Mode.
5 Click OK.
vSphere Administration with the vSphere Client
62 VMware, Inc.