Showing posts with label ESXi. Show all posts
Showing posts with label ESXi. Show all posts

Saturday, August 6, 2016

How to Fix VMware ESXi 6.0 Root Account Lockout and Brute-Force Restrictions

Starting with version 6.0, VMware ESXi introduced an automated security lockout feature that locks the root account after consecutive failed login attempts. On hypervisors exposed to public networks, malicious automated SSH bots frequently trigger this threshold, inadvertently locking legitimate administrators out of the vSphere Client and Web UI.

Security Best Practices: Enforce SSH key-based authentication • Restrict ESXi management firewall to designated administrative IPs.

1. Unlocking the Root Account via Local Console (DCUI)

Log in via the physical or out-of-band Direct Console User Interface (DCUI), navigate to Troubleshooting Options, enable the ESXi Shell, and reset the lockout counter:

# Check failed login attempt count
pam_tally2 --user root

# Reset failed attempt counter and unlock account
pam_tally2 --user root --reset

2. Permanent Hardening: Restrict Management Access

To eliminate unauthorized brute-force attempts permanently:

  1. Disable SSH password logins in /etc/ssh/sshd_config:
    PasswordAuthentication no
  2. Restrict the ESXi management firewall rule for the vSphere Client (port 443 / 902) to your office or VPN gateway IPs:
    esxcli network firewall ruleset set --ruleset-id vSphereClient --allowed-all false
    esxcli network firewall ruleset allowedip add --ruleset-id vSphereClient --ip-address 203.0.113.10

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...