STIGQter STIGQter: STIG Summary:

VMware vSphere 7.0 ESXi Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 02 Apr 2025

CheckedNameTitle
SV-256375r958398_ruleAccess to the ESXi host must be limited by enabling lockdown mode.
SV-256376r959010_ruleThe ESXi host must verify the DCUI.Access list.
SV-256377r959010_ruleThe ESXi host must verify the exception users list for lockdown mode.
SV-256378r958406_ruleRemote logging for ESXi hosts must be configured.
SV-256379r958388_ruleThe ESXi host must enforce the limit of three consecutive invalid logon attempts by a user.
SV-256380r958736_ruleThe ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out.
SV-256381r958390_ruleThe ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via the Direct Console User Interface (DCUI).
SV-256382r958390_ruleThe ESXi host must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via Secure Shell (SSH).
SV-256383r958390_ruleThe ESXi host SSH daemon must be configured with the DOD logon banner.
SV-256384r958408_ruleThe ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.
SV-256385r984206_ruleThe ESXi host Secure Shell (SSH) daemon must ignore ".rhosts" files.
SV-256386r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not allow host-based authentication.
SV-256387r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not allow authentication using an empty password.
SV-256388r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not permit user environment settings.
SV-256389r959010_ruleThe ESXi host Secure Shell (SSH) daemon must perform strict mode checking of home directory configuration files.
SV-256390r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not allow compression or must only allow compression after successful authentication.
SV-256391r959010_ruleThe ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports.
SV-256392r959010_ruleThe ESXi host Secure Shell (SSH) daemon must be configured to not allow X11 forwarding.
SV-256393r959010_ruleThe ESXi host Secure Shell (SSH) daemon must not permit tunnels.
SV-256394r959010_ruleThe ESXi host Secure Shell (SSH) daemon must set a timeout count on idle sessions.
SV-256395r959010_ruleThe ESXi host Secure Shell (SSH) daemon must set a timeout interval on idle sessions.
SV-256396r958412_ruleThe ESXi host must produce audit records containing information to establish what type of events occurred.
SV-256397r984191_ruleThe ESXi host must be configured with a sufficiently complex password policy.
SV-256398r984204_ruleThe ESXi host must prohibit the reuse of passwords within five iterations.
SV-256399r958478_ruleThe ESXi host must disable the Managed Object Browser (MOB).
SV-256400r958478_ruleThe ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH).
SV-256401r958478_ruleThe ESXi host must disable ESXi Shell unless needed for diagnostics or troubleshooting.
SV-256402r958482_ruleThe ESXi host must use Active Directory for local user authentication.
SV-256403r958482_ruleESXi hosts using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory.
SV-256404r958482_ruleActive Directory ESX Admin group membership must not be used when adding ESXi hosts to Active Directory.
SV-256405r970703_ruleThe ESXi host must set a timeout to automatically disable idle shell sessions after two minutes.
SV-256406r970703_ruleThe ESXi host must terminate shell services after 10 minutes.
SV-256407r970703_ruleThe ESXi host must log out of the console UI after two minutes.
SV-256408r958752_ruleThe ESXi host must enable a persistent log location for all locally stored logs.
SV-256409r1038976_ruleThe ESXi host must configure NTP time synchronization.
SV-256410r984242_ruleThe ESXi Image Profile and vSphere Installation Bundle (VIB) acceptance levels must be verified.
SV-256411r958908_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.
SV-256412r958908_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic.
SV-256413r958908_ruleThe ESXi host must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic.
SV-256414r959010_ruleSimple Network Management Protocol (SNMP) must be configured properly on the ESXi host.
SV-256415r959010_ruleThe ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic.
SV-256416r959010_ruleThe ESXi host must disable Inter-Virtual Machine (VM) Transparent Page Sharing.
SV-256417r959010_ruleThe ESXi host must configure the firewall to restrict access to services running on the host.
SV-256418r959010_ruleThe ESXi host must configure the firewall to block network traffic by default.
SV-256419r959010_ruleThe ESXi host must enable Bridge Protocol Data Units (BPDU) filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled.
SV-256420r959010_ruleAll port groups on standard switches must be configured to reject forged transmits.
SV-256421r959010_ruleAll port groups on standard switches must be configured to reject guest Media Access Control (MAC) address changes.
SV-256422r959010_ruleAll port groups on standard switches must be configured to reject guest promiscuous mode requests.
SV-256423r959010_ruleUse of the dvFilter network application programming interfaces (APIs) must be restricted.
SV-256424r959010_ruleAll port groups on standard switches must be configured to a value other than that of the native virtual local area network (VLAN).
SV-256425r959010_ruleAll port groups on standard switches must not be configured to virtual local area network (VLAN) 4095 unless Virtual Guest Tagging (VGT) is required.
SV-256426r959010_ruleAll port groups on standard switches must not be configured to virtual local area network (VLAN) values reserved by upstream physical switches.
SV-256427r959010_ruleThe ESXi host must not provide root/administrator-level access to Common Information Model (CIM)-based hardware monitoring tools or other third-party applications.
SV-256428r959010_ruleThe ESXi host must have all security patches and updates installed.
SV-256429r959010_ruleThe ESXi host must exclusively enable Transport Layer Security (TLS) 1.2 for all endpoints.
SV-256430r959010_ruleThe ESXi host must enable Secure Boot.
SV-256431r1067573_ruleThe ESXi host must use DOD-approved certificates.
SV-256432r959010_ruleThe ESXi host must not suppress warnings that the local or remote shell sessions are enabled.
SV-256433r959010_ruleThe ESXi host must not suppress warnings about unmitigated hyperthreading vulnerabilities.
SV-256434r959010_ruleThe ESXi host Secure Shell (SSH) daemon must disable port forwarding.
SV-256435r959010_ruleThe ESXi host OpenSLP service must be disabled.
SV-256436r959010_ruleThe ESXi host must enable audit logging.
SV-256437r959010_ruleThe ESXi host must enable strict x509 verification for SSL syslog endpoints.
SV-256438r959010_ruleThe ESXi host must verify certificates for SSL syslog endpoints.
SV-256439r959010_ruleThe ESXi host must enable volatile key destruction.
SV-256440r959010_ruleThe ESXi host must configure a session timeout for the vSphere API.
SV-256441r959010_ruleThe ESXi Host Client must be configured with a session timeout.
SV-256442r958408_ruleThe ESXi host rhttpproxy daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.
SV-256443r959010_ruleThe ESXi host must be configured with an appropriate maximum password age.
SV-256444r959010_ruleThe ESXi host must not be configured to override virtual machine (VM) configurations.
SV-256445r959010_ruleThe ESXi host must not be configured to override virtual machine (VM) logger settings.
SV-256446r959010_ruleThe ESXi host must require TPM-based configuration encryption.
SV-256447r959010_ruleThe ESXi host must implement Secure Boot enforcement.
SV-256448r1051419_ruleThe ESXi Common Information Model (CIM) service must be disabled.
SV-256449r959006_ruleThe ESXi host SSH daemon must be configured to only use FIPS 140-2 validated ciphers.