6.0.3

Table Of Contents
Procedure
1 From the Direct Console User Interface, press F2 to access the System Customization menu.
2 Select Troubleshooting Options and press Enter.
3 From the Troubleshooting Mode Options menu, select a service to enable.
n
Enable ESXi Shell
n
Enable SSH
4 Press Enter to enable the service.
5 Press Esc until you return to the main menu of the Direct Console User Interface.
What to do next
Set the availability and idle timeouts for the ESXi Shell. See “Create a Timeout for ESXi Shell Availability in
the Direct Console User Interface,” on page 204 and “Create a Timeout for Idle ESXi Shell Sessions,” on
page 204.
Create a Timeout for ESXi Shell Availability in the Direct Console User Interface
The ESXi Shell is disabled by default. You can set an availability timeout for the ESXi Shell to increase
security when you enable the shell.
The availability timeout seing is the amount of time that can elapse before you must log in after the
ESXi Shell is enabled. After the timeout period, the service is disabled and users are not allowed to log in.
Procedure
1 From the Troubleshooting Mode Options menu, select Modify ESXi Shell and SSH timeouts and press
Enter.
2 Enter the availability timeout.
You must restart the SSH service and the ESXi Shell service for the timeout to take eect.
3 Press Enter and press Esc until you return to the main menu of the Direct Console User Interface.
4 Click OK.
If you are logged in when the timeout period elapses, your session will persist. However, after you log out
or your session is terminated, users are not allowed to log in.
Create a Timeout for Idle ESXi Shell Sessions
If a user enables the ESXi Shell on a host, but forgets to log out of the session, the idle session remains
connected indenitely. The open connection can increase the potential for someone to gain privileged access
to the host. You can prevent this by seing a timeout for idle sessions.
The idle timeout is the amount of time that can elapse before the user is logged out of an idle interactive
sessions. Changes to the idle timeout apply the next time a user logs in to the ESXi Shell and do not aect
existing sessions.
You can specify the timeout from the Direct Console User Interface in seconds, or from the
vSphere Web Client in minutes.
Procedure
1 From the Troubleshooting Mode Options menu, select Modify ESXi Shell and SSH timeouts and press
Enter.
vSphere Security
204 VMware, Inc.