1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere 6.7 ESXi V1R1
  4. ESXI-67-000048 – The ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.

ESXI-67-000048 – The ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.

Details

While encrypted vMotion is available now, vMotion traffic should still be sequestered from other traffic to further protect it from attack. This network must be only be accessible to other ESXi hosts preventing outside access to the network.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configuration of the vMotion VMkernel will be unique to each environment.

As an example, to modify the IP address and VLAN information to the correct network on a distributed switch, do the following:

From the vSphere Client, go to Networking >> Select a distributed switch >> Select a port group >> Configure >> Settings >> Edit >> VLAN.

Change the ‘VLAN Type’ to ‘VLAN’ and change the ‘VLAN ID’ to a network allocated and dedicated to vMotion traffic exclusively.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system VMware.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles