7.1.1 Disable VDS network healthcheck if not used

Information

Disable VDS network healthcheck if not used.

*Rationale*

Network Healthcheck is disabled by default. Once enabled, the healthcheck packets contain
information on host#, vds# port#, which an attacker would find useful. It is recommended
that network healthcheck be used for troubleshooting, and turned off when
troubleshooting is finished.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Using the vSphere Web Client.
2. Select each VDS.
3. Go to Manage > Settings > Health check'.
4. Disable the VLAN and MTU Check and Teaming and Failover Check settings.

Impact-Limit the use of this feature only to when actively troubleshooting VLAN or MTU issues on a VDS.

Default Value-The default value is the prescribed value.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: VMware

Control ID: 9ced77be9f864abe6f8965759ba99a37f09cf9a2b9987385fd79531078eba133