8.1.1 Limit informational messages from the VM to the VMX file

Information

Limit informational messages from the virtual machine to the VMX file to avoid filling the
datastore and causing a Denial of Service (DoS).

*Rationale*

The configuration file containing these name-value pairs is limited to a size of 1MB. This
1MB capacity should be sufficient for most cases, but you can change this value if
necessary. You might increase this value if large amounts of custom information are being
stored in the configuration file. The default limit is 1MB; this limit is applied even when the
sizeLimit parameter is not listed in the .vmx file. Uncontrolled size for the VMX file can
lead to denial of service if the datastore is filled.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'tools.setInfo.sizeLimit' -value 1048576


Default Value-The prescribed state is the default state.

See Also

https://workbench.cisecurity.org/files/145

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4

Plugin: VMware

Control ID: 9aa6e772946fc25b8e2a30649c8cecd9e0a5570675375230c557af3b0a248473