7.8 Ensure port-level configuration overrides are disabled.

Information

Port-level configuration overrides are disabled by default. Once enabled, it allows for different security to be set ignoring what is set at the Port-Group level.

Rationale:

There are cases where unique configurations are needed, but this should be monitored so it is only used when authorized. If overrides are not monitored, anyone who gains access to a VM with a less secure VDS configuration could secretly exploit the broader access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Using the vSphere Web Client,

For each portgroup within each distributed switch

Go to 'Configure' -> 'Settings' -> 'Properties'.

Click 'Edit'

Go to 'Advanced'.

Disable all 'Override port policies'.

See Also

https://workbench.cisecurity.org/benchmarks/8020

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2, CSCv7|12.4

Plugin: VMware

Control ID: f28a323b4bb47e1bcd75275f2ac9007f16cffc79bbfdbc5926d4f9ac68598969