STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 ESXi Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 02 Apr 2025:

The ESXi host must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic.

DISA Rule

SV-256412r958908_rule

Vulnerability Number

V-256412

Group Title

SRG-OS-000423-VMM-001700

Rule Version

ESXI-70-000049

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Select the Management VMkernel and click "Edit...". On the "Port" properties tab, uncheck all services except "Management". Click "OK".

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> Virtual switches.

Find the port group that contains the Management VMkernel and click the "..." button next to the name. Click "Edit Settings".

On the "Properties" tab, change the "VLAN ID" to one dedicated to Management traffic. Click "OK".

Check Contents

From the vSphere Client, select the ESXi host and go to Configure >> Networking >> VMkernel adapters.

Select each VMkernel adapter that is "Enabled" for management traffic and, in the bottom pane, view the "Enabled services".

If any services other than "Management" are enabled on the Management VMkernel adapter, this is a finding.

From the vSphere Client, select the ESXi host and go to Configure >> Networking >> VMkernel adapters.

Review the VLAN associated with each VMkernel that is "Enabled" for management traffic. Verify with the system administrator that they are dedicated for that purpose and are logically separated from other functions.

If the network segment is accessible, except to networks where other management-related entities are located such as vCenter, this is a finding.

If there are any other systems or devices such as VMs on the ESXi management segment, this is a finding.

Vulnerability Number

V-256412

Documentable

False

Rule Version

ESXI-70-000049

Severity Override Guidance

From the vSphere Client, select the ESXi host and go to Configure >> Networking >> VMkernel adapters.

Select each VMkernel adapter that is "Enabled" for management traffic and, in the bottom pane, view the "Enabled services".

If any services other than "Management" are enabled on the Management VMkernel adapter, this is a finding.

From the vSphere Client, select the ESXi host and go to Configure >> Networking >> VMkernel adapters.

Review the VLAN associated with each VMkernel that is "Enabled" for management traffic. Verify with the system administrator that they are dedicated for that purpose and are logically separated from other functions.

If the network segment is accessible, except to networks where other management-related entities are located such as vCenter, this is a finding.

If there are any other systems or devices such as VMs on the ESXi management segment, this is a finding.

Check Content Reference

M

Target Key

5518