SV-258967r961863_rule
V-258967
SRG-APP-000516
VCSA-80-000302
CAT II
10
From the vSphere Client, go to "Networking".
Select a distributed switch >> Select a distributed port group >> Configure >> Settings >> Properties.
Click "Edit".
Select advanced and update "Configure reset at disconnect" to be enabled and click "OK".
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
$pgs = Get-VDPortgroup | Get-View
ForEach($pg in $pgs){
$spec = New-Object VMware.Vim.DVPortgroupConfigSpec
$spec.configversion = $pg.Config.ConfigVersion
$spec.Policy = New-Object VMware.Vim.VMwareDVSPortgroupPolicy
$spec.Policy.PortConfigResetAtDisconnect = $True
$pg.ReconfigureDVPortgroup_Task($spec)
}
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch >> Select a distributed port group >> Configure >> Settings >> Properties.
Review the "Configure reset at disconnect" setting.
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
(Get-VDPortgroup).ExtensionData.Config.Policy.PortConfigResetAtDisconnect
If there are any distributed port groups with "Configure reset at disconnect" configured to "disabled" or "False", this is a finding.
V-258967
False
VCSA-80-000302
If distributed switches are not used, this is not applicable.
From the vSphere Client, go to "Networking".
Select a distributed switch >> Select a distributed port group >> Configure >> Settings >> Properties.
Review the "Configure reset at disconnect" setting.
or
From a PowerCLI command prompt while connected to the vCenter server, run the following command:
(Get-VDPortgroup).ExtensionData.Config.Policy.PortConfigResetAtDisconnect
If there are any distributed port groups with "Configure reset at disconnect" configured to "disabled" or "False", this is a finding.
M
5573