SV-258940r934478_rule
V-258940
SRG-APP-000516
VCSA-80-000273
CAT II
10
From the vSphere Client, go to "Networking".
Select a distributed switch >> Select a distributed port group >> Configure >> Settings >> Policies.
Click "Edit".
Click the "VLAN" tab.
If "VLAN trunking" is not authorized, remove it by setting "VLAN type" to "VLAN" and configure an appropriate VLAN ID. Click "OK".
If "VLAN trunking" is authorized but the range is too broad, modify the range in the "VLAN trunk range" field to the minimum necessary and authorized range. An example range would be "1,3-5,8". Click "OK".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command to configure trunking:
Get-VDPortgroup "Portgroup Name" | Set-VDVlanConfiguration -VlanTrunkRange "<VLAN Range(s) comma separated>"
or
Run this command to configure a single VLAN ID:
Get-VDPortgroup "Portgroup Name" | Set-VDVlanConfiguration -VlanId "<New VLAN#>"
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch >> Select a distributed port group >> Configure >> Settings >> Policies.
Review the port group "VLAN Type" and "VLAN trunk range", if present.
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
Get-VDPortgroup | Where {$_.ExtensionData.Config.Uplink -ne "True"} | Select Name,VlanConfiguration
If any port group is configured with "VLAN trunking" and is not documented as a needed exception (such as NSX appliances), this is a finding.
If any port group is authorized to be configured with "VLAN trunking" but is not configured with the most limited range necessary, this is a finding.
V-258940
False
VCSA-80-000273
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch >> Select a distributed port group >> Configure >> Settings >> Policies.
Review the port group "VLAN Type" and "VLAN trunk range", if present.
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
Get-VDPortgroup | Where {$_.ExtensionData.Config.Uplink -ne "True"} | Select Name,VlanConfiguration
If any port group is configured with "VLAN trunking" and is not documented as a needed exception (such as NSX appliances), this is a finding.
If any port group is authorized to be configured with "VLAN trunking" but is not configured with the most limited range necessary, this is a finding.
M
5573