6.0.3

Table Of Contents
Available services depend on the VIBs that are installed on the ESXi host. You cannot add services without
installing a VIB. Some VMware products, for example, vSphere HA, install VIBs on hosts and make services
and the corresponding rewall ports available.
In a default installation, you can modify the status of the following services from the vSphere Web Client.
Table 58. ESXi Services in the Security Profile
Service Default Description
Direct Console UI Running The Direct Console User Interface (DCUI) service
allows you to interact with an ESXi host from the local
console host using text-based menus.
ESXi Shell Stopped The ESXi Shell is available from the Direct Console
User Interface and includes a set of fully supported
commands and a set of commands for troubleshooting
and remediation. You must enable access to
theESXi Shell from the direct console of each system.
You can enable access to the local ESXi Shell or access
to the ESXi Shell with SSH.
SSH Stopped The host's SSH client service that allows remote
connections through Secure Shell.
Load-Based Teaming Daemon Running Load-Based Teaming.
Local Security Authentication
Server (Active Directory Service)
Stopped Part of Active Directory Service. When you congure
ESXi for Active Directory, this service is started.
I/O Redirector (Active Directory
Service)
Stopped Part of Active Directory Service. When you congure
ESXi for Active Directory, this service is started.
Network Login Server (Active
Directory Service)
Stopped Part of Active Directory Service. When you congure
ESXi for Active Directory, this service is started.
NTP Daemon Stopped Network Time Protocol daemon.
CIM Server Running Service that can be used by Common Information
Model (CIM) applications.
SNMP Server Stopped SNMP daemon. See vSphere Monitoring and Performance
for information on conguring SNMP v1, v2, and v3.
Syslog Server Stopped Syslog daemon. You can enable syslog from the
Advanced System Seings in the vSphere Web Client.
See vSphere Installation and Setup.
vSphere High Availability Agent Stopped Supports vSphere High Availability functionality.
vProbe Daemon Stopped vProbe daemon.
VMware vCenter Agent Running vCenter Server agent. Allows a vCenter Server to
connect to an ESXi host. Specically, vpxa is the
communication conduit to the host daemon, which in
turn communicates with the ESXi kernel.
X.Org Server Stopped X.Org Server. This optional feature is used internally
for 3D graphics for virtual machines.
Enable or Disable a Service in the Security Profile
You can enable or disable one of the services listed in the Security Prole from the vSphere Web Client.
After installation, certain services are running by default, while others are stopped. In some cases,
additional setup is necessary before a service becomes available in the vSphere Web Client UI. For example,
the NTP service is a way of geing accurate time information, but this service only works when required
ports are opened in the rewall.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 179