Ensure that port groups are not configured to VLAN 4095 except for Virtual Guest Tagging (VGT) Details Don’t use VLAN 4095 except for Virtual Guest Tagging (VGT). *Rationale* When a port group is set to VLAN...
Ensure that port groups are not configured to VLAN values reserved by upstream physical switches Details Ensure that port groups are not configured to VLAN values reserved by upstream physical switches *Rationale* Certain physical switches...
Ensure that the Forged Transmits policy is set to reject Details Ensure that the Forged Transmits policy is set to reject. *Rationale* If the virtual machine operating system changes the...
Ensure that the MAC Address Change policy is set to reject Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.wssdk.apiref.doc/vim.host.NetworkPolicy.SecurityPolicy.html Solution 1. Configure by using the vSphere Client to connect to the vCenter Server and logging in as...
Ensure that the Promiscuous Mode policy is set to reject Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.wssdk.apiref.doc/vim.host.NetworkPolicy.SecurityPolicy.html Solution 1. Verify by using the vSphere Client to connect to the vCenter Server and logging in asan...
Ensure that there are no unused ports on a distributed virtual port group Details Ensure that there are no unused ports on a distributed virtual port group. *Rationale* The number of ports available...
Ensure that the vSwitch Forged Transmits policy is set to reject Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.networking.doc/GUID-74E2059A-CC5E-4B06-81B5-3881C80E46CE.html Solution Verify by using the vSphere Client to connect to the vCenter Server and as administrator-1. Go to...
Ensure that the vSwitch MAC Address Change policy is set to reject Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.networking.doc/GUID-74E2059A-CC5E-4B06-81B5-3881C80E46CE.html Solution Using the vSphere Client, connect to the vCenter Server and as administrator-1. Go to ‘Home > Inventory...
Ensure that the vSwitch Promiscuous Mode policy is set to reject Details http://kb.vmware.com/kb/1004099 Solution Using the vSphere Client, connect to the vCenter Server and as administrator-1. Go to ‘Home > Inventory...
Ensure that VDS Netflow traffic is only being sent to authorized collector IP Addresses Details http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.networking.doc/GUID-E19FECAD-8629-4E8A-B61C-1F1C16770B3B.html Solution 1. From the Web or vSphere Clients.2. Configure the Netflow destinations to be correct.3. Edit the VDS...