1. Home
  2. Security Hardening
  3. CIS VMware ESXi 6.7 V1.2.0 L1
  4. Ensure access to VMs through the dvfilter network APIs is configured correctly

Ensure access to VMs through the dvfilter network APIs is configured correctly

Details

A VM must be configured explicitly to accept access by the dvfilter network API. Only VMs that need to be accessed by that API should be configured to accept such access.

Rationale:

An attacker might compromise a VM by making use of the dvfilter API.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To configure a VM to allow dvfilter access, perform the following steps:

Configure the following in the VMX file: ethernet0.filter1.name = dv-filter1 where ethernet0 is the network adapter interface of the virtual machine that is to be protected, filter1 is the number of the filter that is being used, and dv-filter1 is the name of the particular data path kernel module that is protecting the VM.

Set the name of the data path kernel correctly.

To configure a VM to not allow dvfilter access, perform the following steps:

Remove the following from its VMX file: ethernet0.filter1.name = dv-filter1.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management, Identification and Authentication.This control applies to the following type of system VMware.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles