ESXi : firewall-enabled

Information

Configure the ESXi host firewall to restrict access to services running on the host .
Unrestricted access to services running on an ESXi host can expose a host to outside attacks and unauthorized access. Reduce the risk by configuring the ESXi firewall to only allow access from authorized networks.

http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.security.doc/GUID-8912DD42-C6EA-4299-9B10-5F3AEA52C605.html

Solution

From the vSphere web client, select the host and click "Manage" -> "Settings" -> "System" -> "Security Profile".

For each enabled services for both incoming and outgoing connections set a proper network/IP Range after deselecting "Allow connections from any IP address" checkbox.

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vSphere_6_0_Hardening_Guide_GA_15_Jun_2015.xls

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: VMware

Control ID: 11d7ec755858b9ea6b03aa580c1312f7c23a3fc0ca9badde9c56a5070b9db8ec