ESXi : Audit-SSH-Disable

Information

Ensure that the SSH default disablement has not been changed.

SSH is disabled by default on ESXi. The use of SSH to an ESXi host should be limited in scope and use. SSH enablement is controlled via the SSH service. This service is stopped by default.

Solution

In the vSphere Web Client, select the host in the vCenter inventory. Select Configure. In the System Section, select Security Profile and click Edit. Check that the SSH service is reported as Stopped. If it is not, press the Stop button and ensure the Startup Policy is set to "Start and Stop Manually"

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vmware-6-5-update-1-security-configuration-guide.xlsx

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: VMware

Control ID: 37bb829c218f98a3f6f2f008aed28ed7ae3f7515b5ce32525c449f92b0c2d3f1