DSTAVERT wrote:
I do believe though that since it is far easier in vSphere 5 to enable access and to only enable it for a specified interval it that the vast majority of users would be ill advised to summarily disable those alerts. Considering that most corporations have security and auditing policies it may have been better to have made disabling the alert a little more difficult.
I consider it an issue to have it disabled. SSH access utilizes a separate daemon, and often works, even when management services failed.
And vSphere5 has brought us the ESXi firewall, which allows us to enable remote shell and still heavily restrict access to actually connect to it,
as long as we are careful about Layer3 and Layer2 network security in our environment..
Here's why it's such a big issue to not have the 'ESXi shell' always on as backup:
the functionality exists as a troubleshooting option to help solve certain problems.
Given its utility, ease, and convenience for that function, compared to all the cumbersome
or inconvenient alternatives VMware has offered, it's silly/arbitrary to not have that option.
There are reasons SSH and the command line interface of Linux systems are so popular.
Whether VMware acknowledges it or not, the availability of a ESXi shell, a command line interface
_directly_ via SSH/console on the hosts is a huge selling point over Hyper-V (IMO).
I just wish they'd add serial port access to the ESXi shell.
One of the types of problems that can frequently arise is the normal management agents can fail, for example, the daemon
that allows you to connect with the vSphere client and the vSphere API can fail.
As experience has shown with vSphere4, this was probably the number 1 most common issue I had with ESXi,
and the most common reason for me to ever need connect via troubleshooting console was to restart the management services,
or fix the vSwitch so that networking would start functioning again.
Often even the console DCUI would be inoperative or unavailable for one reason or another (probably some sort of host resource consumption thing)
Rebooting the host is certainly not desirable, nor is trying to get someone access to the server room, pray DCUI is working,
and hope the remote hands can follow directions properly.