SV-256350r942490_rule
V-256350
SRG-APP-000516
VCSA-70-000270
CAT II
10
From the vSphere Client, go to "Networking".
Select a distributed switch and then select a port group.
Select Configure >> Settings >> Policies.
Click "Edit".
Click the "Security" tab.
Set "Promiscuous Mode" to "Reject".
Click "OK".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following commands:
Get-VDSwitch | Get-VDSecurityPolicy | Set-VDSecurityPolicy -AllowPromiscuous $false
Get-VDPortgroup | ?{$_.IsUplink -eq $false} | Get-VDSecurityPolicy | Set-VDSecurityPolicy -AllowPromiscuous $false
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch and then select a port group.
Select Configure >> Settings >> Policies.
Verify "Promiscuous Mode" is set to "Reject".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following commands:
Get-VDSwitch | Get-VDSecurityPolicy
Get-VDPortgroup | ?{$_.IsUplink -eq $false} | Get-VDSecurityPolicy
If the "Promiscuous Mode" policy is set to "Accept", and is not documented as an exception, this is a finding.
V-256350
False
VCSA-70-000270
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch and then select a port group.
Select Configure >> Settings >> Policies.
Verify "Promiscuous Mode" is set to "Reject".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following commands:
Get-VDSwitch | Get-VDSecurityPolicy
Get-VDPortgroup | ?{$_.IsUplink -eq $false} | Get-VDSecurityPolicy
If the "Promiscuous Mode" policy is set to "Accept", and is not documented as an exception, this is a finding.
M
5517