vNetwork : restrict-netflow-usage

Information

Ensure that VDS Netflow traffic is only being sent to authorized collector Ips.

The vSphere VDS can export Netflow information about traffic crossing the VDS. Netflow exports are not encrypted and can contain information about the virtual network making it easier for a MITM attack to be executed successfully. If Netflow export is required, verify that all VDS Netflow target IP's are correct.

http://pubs.vmware.com/vsphere-65/topic/com.vmware.vsphere.security.doc/GUID-FA661AE0-C0B5-4522-951D-A3790DBE70B4.html

http://pubs.vmware.com/vsphere-65/topic/com.vmware.vsphere.networking.doc/GUID-55FCEC92-74B9-4E5F-ACC0-4EA1C36F397A.html

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From vSphere Web Client, for each distributed switch go to "Configure" -> "Settings" -> "NetFlow". Click "Edit" and set the "Collector IP address" and "Collector port" as appropriate.

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vmware-6-5-update-1-security-configuration-guide.xlsx