Starting with version 6.0, VMware ESXi introduced an automated security lockout feature that locks the root account after consecutive failed login attempts. On hypervisors exposed to public networks, malicious automated SSH bots frequently trigger this threshold, inadvertently locking legitimate administrators out of the vSphere Client and Web UI.
1. Unlocking the Root Account via Local Console (DCUI)
Log in via the physical or out-of-band Direct Console User Interface (DCUI), navigate to Troubleshooting Options, enable the ESXi Shell, and reset the lockout counter:
# Check failed login attempt count
pam_tally2 --user root
# Reset failed attempt counter and unlock account
pam_tally2 --user root --reset
2. Permanent Hardening: Restrict Management Access
To eliminate unauthorized brute-force attempts permanently:
- Disable SSH password logins in
/etc/ssh/sshd_config:PasswordAuthentication no - Restrict the ESXi management firewall rule for the vSphere Client (port 443 / 902) to your office or VPN gateway IPs:
esxcli network firewall ruleset set --ruleset-id vSphereClient --allowed-all false esxcli network firewall ruleset allowedip add --ruleset-id vSphereClient --ip-address 203.0.113.10