SV-207636r378841_rule
V-207636
SRG-OS-000095-VMM-000480
ESXI-65-000035
CAT II
10
From the vSphere Web Client select the ESXi Host and go to Configure >> System >> Security Profile. Under Services select Edit then select the SSH service and click the Stop button to stop the service. Use the pull-down menu to change the Startup policy to "Start and stop manually" and click OK.
or
From a PowerCLI command prompt while connected to the ESXi host run the following commands:
Get-VMHost | Get-VMHostService | Where {$_.Label -eq "SSH"} | Set-VMHostService -Policy Off
Get-VMHost | Get-VMHostService | Where {$_.Label -eq "SSH"} | Stop-VMHostService
From the vSphere Web Client select the ESXi Host and go to Configure >> System >> Security Profile. Under Services select Edit and view the "SSH" service and verify it is stopped.
or
From a PowerCLI command prompt while connected to the ESXi host run the following command:
Get-VMHost | Get-VMHostService | Where {$_.Label -eq "SSH"}
If the ESXi SSH service is running, this is a finding.
V-207636
False
ESXI-65-000035
From the vSphere Web Client select the ESXi Host and go to Configure >> System >> Security Profile. Under Services select Edit and view the "SSH" service and verify it is stopped.
or
From a PowerCLI command prompt while connected to the ESXi host run the following command:
Get-VMHost | Get-VMHostService | Where {$_.Label -eq "SSH"}
If the ESXi SSH service is running, this is a finding.
M
2925