STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 ESXi Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic.

DISA Rule

SV-258759r958908_rule

Vulnerability Number

V-258759

Group Title

SRG-OS-000423-VMM-001700

Rule Version

ESXI-80-000199

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configuration of an IP-Based VMkernel will be unique to each environment.

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Select the VMkernel used for IP-based storage and click "Edit". On the "Port" properties tab, uncheck all services. Click "OK".

Note: For VMkernels used for vSAN leave the vSAN service enabled and uncheck all others.

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> Virtual switches.

Find the port group that is dedicated to IP-based storage and click the '...' button next to the name. Click "Edit Settings".

On the "Properties" tab, change the "VLAN ID" to one dedicated for IP-based storage traffic. Click "OK".

Check Contents

If IP-based storage is not used, this is not applicable.

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Review each VMkernel adapter that is used for IP-based storage traffic and view the "Enabled services".

Review the VLAN associated with each VMkernel that is used for IP-based storage traffic. Verify with the system administrator that they are dedicated for that purpose and are logically separated from other functions.

If any services are enabled on an NFS or iSCSI IP-based storage VMkernel adapter, this is a finding.

If any services are enabled on a vSAN VMkernel adapter other than vSAN, this is a finding.

If any IP-based storage networks are not isolated from other traffic types, this is a finding.

Vulnerability Number

V-258759

Documentable

False

Rule Version

ESXI-80-000199

Severity Override Guidance

If IP-based storage is not used, this is not applicable.

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> Networking >> VMkernel adapters.

Review each VMkernel adapter that is used for IP-based storage traffic and view the "Enabled services".

Review the VLAN associated with each VMkernel that is used for IP-based storage traffic. Verify with the system administrator that they are dedicated for that purpose and are logically separated from other functions.

If any services are enabled on an NFS or iSCSI IP-based storage VMkernel adapter, this is a finding.

If any services are enabled on a vSAN VMkernel adapter other than vSAN, this is a finding.

If any IP-based storage networks are not isolated from other traffic types, this is a finding.

Check Content Reference

M

Target Key

5562