SV-256347r885652_rule
V-256347
SRG-APP-000516
VCSA-70-000267
CAT III
10
From the vSphere Client, go to "Networking".
Select a distributed switch >> Configure >> Settings >> Health Check.
Click "Edit".
Disable the "VLAN and MTU" and "Teaming and failover" checks.
Click "OK".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
Get-View -ViewType DistributedVirtualSwitch | ?{($_.config.HealthCheckConfig | ?{$_.enable -notmatch "False"})}| %{$_.UpdateDVSHealthCheckConfig(@((New-Object Vmware.Vim.VMwareDVSVlanMtuHealthCheckConfig -property @{enable=0}),(New-Object Vmware.Vim.VMwareDVSTeamingHealthCheckConfig -property @{enable=0})))}
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch >> Configure >> Settings >> Health Check.
View the health check pane and verify the "VLAN and MTU" and "Teaming and failover" checks are "Disabled".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following commands:
$vds = Get-VDSwitch
$vds.ExtensionData.Config.HealthCheckConfig
If the health check feature is enabled on distributed switches and is not on temporarily for troubleshooting purposes, this is a finding.
V-256347
False
VCSA-70-000267
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch >> Configure >> Settings >> Health Check.
View the health check pane and verify the "VLAN and MTU" and "Teaming and failover" checks are "Disabled".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following commands:
$vds = Get-VDSwitch
$vds.ExtensionData.Config.HealthCheckConfig
If the health check feature is enabled on distributed switches and is not on temporarily for troubleshooting purposes, this is a finding.
M
5517