Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Deploy Dell PowerFlex v3.6.x

PDF

Configure ESXi security settings

Before deploying PowerFlex systems, you must configure some VMware security features. This procedure describes how to perform the security configurations using the vSphere web client.

Prerequisites

Ensure that you have:
  • IP address of VMware vCenter server
  • User name and password for accessing the vCenter with the vSphere Web Client

About this task

NOTE: Ensure that the remote connection is established within 1 to 2 minutes. Otherwise, lockdown mode is enabled on the ESXi servers, preventing you from subsequent remote connectivity. When in lockdown mode, you can connect to the ESXi servers locally.

Steps

  1. Log in to the vSphere web client.
    The vSphere Web Client window is displayed with Navigator and Home panes. The Navigator pane displays network entities as nodes, and the Home pane displays network entities as icons.
  2. In the Navigator pane, select Home > Hosts and Clusters.
    Preconfigured hosts, clusters, and datacenters are displayed as navigation tree nodes, in the Navigator pane.
  3. Configure the security-related parameters:
    1. In the Navigator pane, select an ESXi server from a host, cluster, or datacenter node .
    2. From the Manage tab, select Settings > System > Advanced System Settings.
      A list of system-defined parameters with predefined parameter values is displayed.
    3. In the Search field, find the following security parameters:
      • Set Security.AccountLockFailures = 0

        The parameter value defines the maximum number of failed login attempts allowed, before locking out the user's account. The zero (0) value disables account locking.

        NOTE: To disable the locking out of user accounts, the parameter value must be set as zero (0).
      • Set Security.AccountUnlockTime = 1 (in seconds)

        The parameter value defines the duration in seconds to lock out a user's account, after exceeding the maximum number of allowed failed login attempts.

        NOTE: For ease of operation, it is recommended that the parameter value be set as 1 or 2 seconds.
    4. If required, click Edit and update the security parameter values.
  4. Configure the Lockdown Mode parameter:
    1. From the Manage tab, select Settings > System > Security Profile.
    2. Scroll to the Lockdown Mode pane and verify the value of the Lockdown Mode parameter.
    3. Verify that Lockdown Mode is set to Disabled.
      If Lockdown mode is not disabled, click Edit and change the parameter value to Disabled.
  5. Configure the SSH parameter:
    1. From the Manage tab, select Settings > System > Security Profile.
    2. Scroll to the Services pane and verify the SSH option.

      Services pane
    3. SSH must be running. If SSH is stopped, change its status to Running:
      1. In the Services pane, click Edit.
      2. In the Edit Security Profile dialog boc, select the SSH parameter.

        The SSH status is Stopped.

      3. Click Start.

        The SSH status changes to Running.

      4. Click OK

        SSH status changes to Running.

  6. Restart the management service or restart the server.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\