7.1.3 Ensure that the Promiscuous Mode policy is set to reject

Information

http://pubs.vmware.com/vsphere-51/topic/com.vmware.wssdk.apiref.doc/vim.host.NetworkPolicy.SecurityPolicy.html

Solution

1. Verify by using the vSphere Client to connect to the vCenter Server and logging in as
an administrator.
2. Go to 'Home > Inventory > Networking'.
3. Select each dvPortgroup connected to active VMs requiring securing.
4. Go to tab 'Summary > Edit Settings > Policies > Security'.
5. Configure 'Promiscuous Mode' = 'Reject'

Impact-Security devices that require the ability to see all packets on a vSwitch will not operate
properly if the Promiscuous Mode parameter is set to Reject.

Default Value-Promiscuous mode is disabled by default. This is the prescribed setting.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: VMware

Control ID: aa6a9a8aa2820244050b994998ea19a3df076af12e8fd285eea36be8f07a6484