2.3 Disable Managed Object Browser (MOB)

Information

http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.security.doc/GUID-0EF83EA7-277C-400B-B697-04BDC9173EA3.html

Solution

To implement the recommended configuration state, run the following ESXi shell
command-vim-cmd proxysvc/remove_service '/mob' 'httpsWithRedirect'Note- You cannot disable the MOB while a host is in lockdown mode.

Impact-The MOB will no longer be available for diagnostics. Some 3rd party tools use this interface
to gather information. Testing should be done after disabling the MOB to verify 3rd party
applications are still functioning as expected.To re-enable the MOB temporarily- ~ # vim-cmd proxysvc/add_np_service '/mob' httpsWithRedirect /var/run/vmware/proxy-mob

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|MP-2

Plugin: VMware

Control ID: d0d3c685f16c07e784499f1241bc6e130de20082ec2d685ecd320c018107b5f8