1. Home
  2. Security Hardening
  3. DISA STIG VMware ESXi VCenter 5 STIG V2R1
  4. VCENTER-000034 – The Update Manager must not directly connect to public patch repositories on the Internet.

VCENTER-000034 – The Update Manager must not directly connect to public patch repositories on the Internet.

Details

In a typical deployment, the Update Manager connects to public patch repositories on the Internet to download patches. Any channel to the Internet represents a threat. For security reasons and deployment restrictions, the Update Manager must be installed in a secured network that is disconnected from the Internet.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To configure a Web server or local disk repository as a download source (i.e., ‘Direct connection to Internet’ must not be selected as the source), from the vSphere Client/vCenter Server system, click Update Manager under Solutions and Applications. On the Configuration tab, under Settings, click Download Settings. In the Download Sources pane, select Use a shared repository. Enter the path or the URL to the shared repository. Click Validate URL to validate the path. Click Apply.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system VMware.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles