メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。
一部の文書番号が変更されている可能性があります。探しているものではない場合は、すべての文書を検索してみてください。文書の検索

Dell VxRail: ESXi Root Account is Locked for 900 s After Login Attempts Fails

概要: This article provides a resolution when remote access for the ESXi local user account root is locked for 900 s after failed login attempts. Connect to the iDRAC console to access the ESXi shell then run the reset command. ...

この記事は自動翻訳されたものである可能性があります。品質に関するフィードバックがある場合は、このページの下部にあるフォームを使用してお知らせください。

文書の内容


現象

The root account of one or more ESXi hosts is locked due to several failed login attempts.

Unable to connect to the node using SSH or the web UI.

Confirm the issue using the iDRAC console to the ESXi shell.

In vCenter, a warning message is shown similar to the following:

Remote access for ESXi local user account 'root' has been locked for 900s after 14 failed login attempts.

Remote access locked message

Figure 1: Remote access is locked.

Logs similar to the following are found on the affected host:

/var/log/vobd.log

2020-04-03T17:27:58.790Z: [GenericCorrelator] 8202447897096us: [vob.user.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
2020-04-03T17:27:58.790Z: [UserLevelCorrelator] 8202447897096us: [vob.user.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
2020-04-03T17:27:58.791Z: [UserLevelCorrelator] 8202447897325us: [esx.audit.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.

 

/var/log/auth.log

2020-04-03T17:29:06Z sshd[701694298]: Connection from 192.168.100.40 port 55682
2020-04-03T17:29:06Z sshd[701333862]: pam_tally2(sshd:auth): user root (0) tally 34, deny 5
2020-04-03T17:29:08Z sshd[701694298]: error: PAM: Authentication failure for root from 192.168.100.40
2020-04-03T17:29:08Z sshd[701694492]: pam_tally2(sshd:auth): user root (0) tally 35, deny 5
2020-04-03T17:29:08Z sshd[701694492]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.100.40  user=root
2020-04-03T17:29:10Z sshd[701694298]: error: PAM: Authentication failure for root from 192.168.100.40
2020-04-03T17:29:10Z sshd[701694298]: error: Received disconnect from 192.168.100.40 port 55682:3: com.jcraft.jsch.JSchException: Auth cancel [preauth]
2020-04-03T17:29:10Z sshd[701694298]: Disconnected from authenticating user root 192.168.100.40 port 55682 [preauth]

原因

The root password for the node may have been changed, but the third-party monitoring software has not been updated with the new root password.

This causes multiple failed logins (sometimes hundreds or even thousands). This locks the root account for 15 minutes which leads to the inability to SSH to the node or log in to the node web UI.

You can log in through the DCUI and the ESXi shell.

Starting with vSphere 6.0, account locking is supported for access through SSH and through the vSphere Web Services SDK. The Direct Console Interface (DCUI) and the ESXi Shell do not support account lockout. By default, a maximum of five failed attempts are allowed before the account is locked. The account is unlocked after 15 minutes by default.

解決方法

To address this issue:
  1. Connect to the iDRAC console and then to the ESXi shell.
  2. Enable the shell by logging in to the DCUI and enabling the ESXi shell under troubleshooting options.
  3. You can also do a Cntrl-Alt-F1 to access the shell.
  4. After connecting to the ESXi shell, run the commands below. The output should match the screenshot below, except the "From" entry says "unknown."
#pam_tally2 --user root
#pam_tally2 --user root --reset
#pam_tally2 --user root
ESXi commands and output Figure 2: ESXi commands and output
  1. After running the above commands, log in to the ESXi node web UI.
  2. Go to Monitor and then Events. You should see an IP address that was trying to log in that is listed as failed.
  3. You must identify the application based on the IP address that is listed here. Either stop it or configure it with the correct credentials.

その他の情報

For more information, see VMware article ESXi Passwords and Account LockoutThis hyperlink is taking you to a website outside of Dell Technologies..

Watch this video on ESXi Break Fix Unlock root User Account.

Duration: 00:04:56 (hh:mm:ss)
When available, closed caption (subtitles) language settings can be chosen using the Settings or CC icon on this video player.

Related Resources
Here are some recommended resources related to this topic that might be of interest:

文書のプロパティ


影響を受ける製品

VxRail, VxRail E560F

最後に公開された日付

14 6月 2024

バージョン

13

文書の種類

Solution