ESXI-06-000051 - The system must protect the confidentiality and integrity of transmitted information.

Information

There are now six types of management VMkernels that can be created for different types of traffic. In order to protect these types of management traffic admins must logically separate these onto different networks and dedicate VMkernel ports to each.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Web Client select the ESXi Host and go to Manage >> Networking >> VMkernel adapters >> Select a VMkernel Adapter >> Click Edit >> Uncheck any additional services that have been enabled on the VMkernel adapter so that there is only one service left checked.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMware_vSphere_6-0_ESXi_V1R5_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8, CAT|III, CCI|CCI-002418, Group-ID|V-63271, Rule-ID|SV-77761r1_rule, STIG-ID|ESXI-06-000051, Vuln-ID|V-63271

Plugin: VMware

Control ID: 65ed702d8fe950d71755cfc48d61630fbd79fd7ea47d329c842d28b3b9a8c111