2.6 Ensure dvfilter API is not configured if not used

Information

The dvfilter network API is used by some products (e.g., VMSafe). If it is not in use, it
should not be configured to send network information to a VM.


*Rationale*

If the dvfilter network API is enabled in the future and it is already configured, an attacker might attempt to connect
a VM to it, thereby potentially providing access to the network of other VMs on the host.

Solution

To remove the configuration for the dvfilter network API, perform the following from the vSphere web client:

1. Select the host and click "Configure" -> "System" -> "Advanced System Settings".
2. Enter Net.DVFilterBindIpAddress in the filter.
3. Set Net.DVFilterBindIpAddress to an empty value.
4. If an appliance is being used, make sure the value of this parameter is set to the
proper IP address.
5. Make sure the attribute is highlighted, then click the pencil icon.
6. Enter the proper IP address.
7. Click "OK".

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: VMware

Control ID: 9f3ef7a2253c51a6f1ef12fdbd8f87b4c659400c2a93ab89d3b80aeb60b2f198