SV-279486r1192542_rule
V-279486
SRG-APP-000211-AS-000146
NXAC-AS-000089
CAT II
10
Configure management information flow to isolate to a separate VLAN from the guest VMs.
1. Log in to Prism Element.
2. Click the gear icon in the upper-right corner.
3. Under the "Settings" menu, click "Network Configuration", then select the "Internal Interfaces" tab.
4. Click "Management LAN".
5. Set the VLAN to the VLAN used for management functions.
a. SSH into each CVM host as user "Nutanix" and issue the following command:
change_cvm_vlan vlan_id.
b. SSH into each AHV host as root and issue the following command:
ovs-vsctl set port br0 tag=vlan_id
Note: All network switches connected to Nutanix nodes must be appropriately configured with the same VLAN ID.
Management information flow can be isolated to a separate VLAN from the guest VMs. Verify a management LAN is configured.
1. Log in to Prism Element.
2. Click the gear icon in the upper right-corner.
3. Under the "Settings" menu, click "Network Configuration", then select the "Internal Interfaces" tab.
4. Click "Management LAN".
If "VLAN ID" is "0" or blank, this is a finding.
V-279486
False
NXAC-AS-000089
Management information flow can be isolated to a separate VLAN from the guest VMs. Verify a management LAN is configured.
1. Log in to Prism Element.
2. Click the gear icon in the upper right-corner.
3. Under the "Settings" menu, click "Network Configuration", then select the "Internal Interfaces" tab.
4. Click "Management LAN".
If "VLAN ID" is "0" or blank, this is a finding.
M
5729