8.4.1 Control access to VMs through the dvfilter network APIs

Information

http://kb.vmware.com/kb/1028151

Solution

If a VM is supposed to be protected-. Configure the following in its VMX file- ethernet0.filter1.name = dv-
filter1 where ethernet0 is the network adapter interface of the virtual machine
that is to be protected, filter1 is the number of the filter that is being used, and dv-
filter1 is the name of the particular data path kernel module that is protecting the
VM.
. Ensure that the name of the data path kernel is set correctly.If a VM is not supposed to be protected-. Remove the following from its VMX file- ethernet0.filter1.name = dv-
filter1 where ethernet0 is the network adapter interface of the virtual machine
that is to be protected, filter1 is the number of the filter that is being used, and dv-
filter1 is the name of the particular data path kernel module that is protecting the
VM.

Impact-Incorrectly configuring this option can negatively impact functionality of tools that use
vmsafe API.Incorrectly configuring this option can prevent VMs from connecting to the network.

Default Value-The prescribed state is the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: VMware

Control ID: 07941006b0b63d4083ebab69cf397d17e48ba5a9b0eee5a5963cde7b95f12500