6.0

Table Of Contents
n
Users dened in the DCUI.Access advanced option for the host. This
option is for emergency access to the Direct Console Interface in case the
connection to vCenter Server is lost. These users do not require
administrative privileges on the host.
Strict Lockdown Mode
In strict lockdown mode, which is new in vSphere 6.0, the DCUI service is
stopped. If the connection to vCenter Server is lost and the
vSphere Web Client is no longer available, the ESXi host becomes
unavailable, unless the ESXi Shell and SSH services are enabled and
Exception Users are dened. If you cannot restore the connection to the
vCenter Server system, you must reinstall the host.
Lockdown Mode and the ESXi Shell and SSH Services
Strict lockdown mode stops the DCUI service. However, the ESXi Shell and SSH services are independent of
lockdown mode. For lockdown mode to be an eective security measure, ensure that ESXi Shell and SSH
services are also disabled. These services are disabled by default.
When a host is in lockdown mode, users on the Exception Users list can access the host from the ESXi Shell
and through SSH if they have the Administrator role on the host. This access is possible even in strict
lockdown mode. Leaving the ESXi Shell service and the SSH service disabled is the most secure option.
N The Exception Users list is meant for service accounts that perform specic tasks such as host
backups, and not for administrators. Adding administrator users to the Exception Users list defeats the
purpose of lockdown mode.
Put an ESXi Host in Normal Lockdown Mode by Using the VMware Host Client
You can use the VMware Host Client to enter normal lockdown mode.
Procedure
1 Right-click Host in the VMware Host Client inventory, select Lockdown mode from the drop-down
menu, and select Enter normal lockdown.
A warning message appears.
2 Click Enter normal lockdown.
Put an ESXi Host in Strict Lockdown Mode by Using the VMware Host Client
You can use the VMware Host Client to enter strict lockdown mode.
Procedure
1 Right-click Host in the VMware Host Client inventory, select Lockdown mode from the drop-down
menu, and select Enter strict lockdown.
The warning message appears.
2 Click Enter strict lockdown.
Chapter 2 Host Management with the VMware Host Client
VMware, Inc. 29