1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere 6.7 ESXi V1R1
  4. ESXI-67-000049 – The ESXi host must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic.

ESXI-67-000049 – The ESXi host must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic.

Details

The vSphere management network provides access to the vSphere management interface on each component. Services running on the management interface provide an opportunity for an attacker to gain privileged access to the systems. Any remote attack most likely would begin with gaining entry to this network.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Client, select the ESXi host and go to Configure >> Networking >> VMkernel adapters.

Select the Management VMkernel and click ‘Edit’.

On the Port properties tab, uncheck everything but ‘Management.’

On the IP Settings tab, enter the appropriate IP address and subnet information and click ‘OK’.

Set the appropriate VLAN ID >> Configure >> Networking >> Virtual switches.

Select the Management portgroup and click ‘Edit’.

On the properties tab, enter the appropriate VLAN ID and click ‘OK’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system VMware.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles