7.8 Ensure port-level configuration overrides are disabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Port-level configuration overrides are disabled by default. Once enabled, it allows for different security to be set ignoring what is set at the Port-Group level.

Rationale:

There are cases where unique configurations are needed, but this should be monitored so it is only used when authorized. If overrides are not monitored, anyone who gains access to a VM with a less secure VDS configuration could secretly exploit the broader access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Using the vSphere Web Client,

For each portgroup within each distributed switch

Go to 'Configure' -> 'Settings' -> 'Properties'.

Click 'Edit'

Go to 'Advanced'.

Disable all 'Override port policies'.

See Also

https://workbench.cisecurity.org/files/3511