Disable VDS network healthcheck if not used Details Disable VDS network healthcheck if not used. *Rationale* Network Healthcheck is disabled by default. Once enabled, the healthcheck packets...
Disable VM communication through VMCI Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.ICbase/PDF/ws8x_esx51_vmci_sockets.pdf Solution To implement the recommended configuration state, run the following PowerCLIcommand-# Add the setting to all VMsGet-VM |...
Disconnect unauthorized devices – CD/DVD Devices Details Any enabled or connected device represents a potential attack channel. Users and processes without privileges on a virtual machine...
Disconnect unauthorized devices – Floppy Devices Details Any enabled or connected device represents a potential attack channel. Users and processes without privileges on a virtual machine...
Do not use default self-signed certificates for ESXi communication Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.security.doc/GUID-A261E6D8-03E4-48ED-ADB6-473C2DAAB7AD.html Solution Leverage VMware’s SSL Certificate Automation Tool to install CA-signed SSL certificates. Fore more information on this tool,...
Enable bidirectional CHAP authentication for iSCSI traffic Details By enabling bidirectional CHAP authentication, an additional level of security enables the initiator to authenticate the target. *Rationale* vSphere...
Enable lockdown mode to restrict remote access Details http://kb.vmware.com/kb/1008077 Solution From the vSphere web client-1. Select the host2. Select ‘Manage’ -> ‘Security Profile’.3. Scroll down to ‘Lockdown...
Ensure proper SNMP configuration- ‘community name private does not exist’ Details Verify that SNMP (Simple Network Management Protocol) is configured and that all the settings are correct. If SNMP is...
Ensure proper SNMP configuration- ‘community name public does not exist’ Details Verify that SNMP (Simple Network Management Protocol) is configured and that all the settings are correct. If SNMP is...
Ensure that port groups are not configured to the value of the native VLAN Details Do not use Native VLAN ID 1. *Rationale* ESXi does not use the concept of native VLAN. Frames with...