SV-256411r958908_rule
V-256411
SRG-OS-000423-VMM-001700
ESXI-70-000048
CAT II
10
Configuration of the vMotion VMkernel will be unique to each environment.
As an example, to modify the IP address and VLAN information to the correct network on a distributed switch do the following:
From the vSphere Client, go to Networking.
Select a distributed switch, select a port group, and then go to Configure >> Settings >> Edit >> VLAN.
Change the "VLAN Type" to "VLAN" and change the "VLAN ID" to a network allocated and dedicated to vMotion traffic exclusively.
For environments that do not use vCenter server to manage ESXi, this is not applicable.
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> Networking.
Review the VLAN associated with the vMotion VMkernel(s) and verify they are dedicated for that purpose and are logically separated from other functions.
If long distance or cross vCenter vMotion is used, the vMotion network can be routable but must be accessible to only the intended ESXi hosts.
If the vMotion port group is not on an isolated VLAN and/or is routable to systems other than ESXi hosts, this is a finding.
V-256411
False
ESXI-70-000048
For environments that do not use vCenter server to manage ESXi, this is not applicable.
From the vSphere Client, go to Hosts and Clusters.
Select the ESXi Host >> Configure >> Networking.
Review the VLAN associated with the vMotion VMkernel(s) and verify they are dedicated for that purpose and are logically separated from other functions.
If long distance or cross vCenter vMotion is used, the vMotion network can be routable but must be accessible to only the intended ESXi hosts.
If the vMotion port group is not on an isolated VLAN and/or is routable to systems other than ESXi hosts, this is a finding.
M
5518