7.6 Ensure port groups are not configured to VLAN 4095 except for Virtual Guest Tagging (VGT)

Information

Port groups should not be configured to VLAN 4095 except for Virtual Guest Tagging (VGT).
When a port group is set to VLAN 4095, this activates VGT mode. In this mode, the vSwitch
passes all network frames to the guest virtual machine without modifying the VLAN tags,
leaving it up to the guest to deal with them. VLAN 4095 should be used only if the guest has
been specifically configured to manage VLAN tags itself.

*Rationale*

If VGT is enabled inappropriately, it might cause a denial of service or allow a guest virtual
machine to interact with traffic on an unauthorized VLAN.

Solution

VLAN ID setting on all port groups should not be set to 4095 unless VGT is required.

1. From the vSphere web client select the host.
2. On the Configure tab, click Networking, and select Virtual switches.
3. Select a standard switch from the list.
4. The topology diagram of the switch appears showing the various port groups
associated with that switch.
5. For each port group on the vSwitch, verify and record the VLAN IDs used.
6. If a VLAN ID change is needed click the name of the port group in the topology
diagram of the virtual switch.
7. Click the 'Edit settings' pencil icon under the topology diagram title.
8. In the Properties section, name the port group in the Network Label text field.
9. Choose an existing VLAN ID drop-down menu or type in a new one.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: VMware

Control ID: e0b6f71a8f6ac37bfe7fffe1e86d1fd804bca1ef0a7ee039abe600afbf18180a