7.6 Ensure that port groups are not configured to VLAN 4095 except for Virtual Guest Tagging (VGT)

Information

Don't use VLAN 4095 except for Virtual Guest Tagging (VGT).

*Rationale*

When a port group is set to VLAN 4095, this activates VGT mode. In this mode, the vSwitch
passes all network frames to the guest VM without modifying the VLAN tags, leaving it up
to the guest to deal with them. VLAN 4095 should be used only if the guest has been
specifically configured to manage VLAN tags itself. If VGT is enabled inappropriately, it
might cause denial of service or allow a guest VM to interact with traffic on an
unauthorized VLAN.

Solution

VLAN ID setting on all port groups should not be set to 4095 unless VGT is required.1. From the vSphere web client select the host.
2. On the Manage tab, click Networking, and select Virtual switches.
3. Select a standard switch from the list.
4. The topology diagram of the switch appears showing the various port groups
associated with that switch.
5. For each port group on the vSwitch, verify and record the VLAN IDs used.
6. If a VLAN ID change is needed click the name of the port group in the topology
diagram of the virtual switch.
7. Click the 'Edit settings' pencil icon under the topology diagram title.
8. In the Properties section, name the port group in the Network Label text field.
9. Choose an existing VLAN ID drop-down menu or type in a new one.

See Also

https://workbench.cisecurity.org/files/145

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: VMware

Control ID: a00085e4bce923fc45c84fb4cf6074b3fb4098f0be618fecb7a1a1f15d778615