STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 ESXi Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 31 Oct 2023:

The ESXi host must protect the confidentiality and integrity of transmitted information by isolating ESXi management traffic.

DISA Rule

SV-258758r933335_rule

Vulnerability Number

V-258758

Group Title

SRG-OS-000423-VMM-001700

Rule Version

ESXI-80-000198

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configuration of the management VMkernel will be unique to each environment.

For example, to modify the IP address and VLAN information to the correct network on a distributed switch, do the following:

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Select the Management VMkernel and click "Edit". On the Port properties tab, uncheck all services except for "Management". Click "OK".

From the vSphere Client, go to Networking.

Select a distributed switch >> Select a port group >> Configure >> Settings >> Properties.

Click "Edit" and select VLAN.

Change the "VLAN Type" to "VLAN" and change the "VLAN ID" to a network allocated and dedicated to management traffic exclusively. Click "OK".

Check Contents

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Review each VMkernel adapter that is used for management traffic and view the "Enabled services".

Review the VLAN associated with each VMkernel that is used for management traffic. Verify with the system administrator that they are dedicated for that purpose and are logically separated from other functions.

If any services other than "Management" are enabled on the Management VMkernel adapter, this is a finding.

If the network segment is accessible, except to networks where other management-related entities are located such as vCenter, this is a finding.

If there are any other systems or devices such as VMs on the ESXi management segment, this is a finding.

Vulnerability Number

V-258758

Documentable

False

Rule Version

ESXI-80-000198

Severity Override Guidance

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Review each VMkernel adapter that is used for management traffic and view the "Enabled services".

Review the VLAN associated with each VMkernel that is used for management traffic. Verify with the system administrator that they are dedicated for that purpose and are logically separated from other functions.

If any services other than "Management" are enabled on the Management VMkernel adapter, this is a finding.

If the network segment is accessible, except to networks where other management-related entities are located such as vCenter, this is a finding.

If there are any other systems or devices such as VMs on the ESXi management segment, this is a finding.

Check Content Reference

M

Target Key

5562