SV-258717r959010_rule
V-258717
SRG-OS-000480-VMM-002000
VMCH-80-000204
CAT II
10
For each virtual machine do the following:
From the vSphere Client, right-click the Virtual Machine and go to Edit Settings >> VM Options >> Encryption.
For "Encrypted FT" set the value to "Opportunistic" or "Required". Click "OK".
or
From a PowerCLI command prompt while connected to the ESXi host or vCenter server, run the following commands:
$spec = New-Object VMware.Vim.VirtualMachineConfigSpec
$spec.FTEncryption = New-Object VMware.Vim.VMware.Vim.VirtualMachineConfigSpecEncryptedFtModes
$spec.FT = ftEncryptionOpportunistic or ftEncryptionRequired
(Get-VM -Name <vmname>).ExtensionData.ReconfigVM($spec)
If the Virtual Machine does not have Fault Tolerance enabled, this is not applicable.
For each virtual machine do the following:
From the vSphere Client, right-click the Virtual Machine and go to Edit Settings >> VM Options >> Encryption.
or
From a PowerCLI command prompt while connected to the ESXi host or vCenter server, run the following command:
Get-VM | Where {($_.ExtensionData.Config.FtEncryptionMode -ne "ftEncryptionOpportunistic") -and ($_.ExtensionData.Config.FtEncryptionMode -ne "ftEncryptionRequired")}
If the "Encrypted FT" setting does not have a value of "Opportunistic" or "Required", this is a finding.
V-258717
False
VMCH-80-000204
If the Virtual Machine does not have Fault Tolerance enabled, this is not applicable.
For each virtual machine do the following:
From the vSphere Client, right-click the Virtual Machine and go to Edit Settings >> VM Options >> Encryption.
or
From a PowerCLI command prompt while connected to the ESXi host or vCenter server, run the following command:
Get-VM | Where {($_.ExtensionData.Config.FtEncryptionMode -ne "ftEncryptionOpportunistic") -and ($_.ExtensionData.Config.FtEncryptionMode -ne "ftEncryptionRequired")}
If the "Encrypted FT" setting does not have a value of "Opportunistic" or "Required", this is a finding.
M
5563