ESXi: esxi-8.vmk-management

Information

The ESXi host must isolate management communications. VMkernel network interfaces that are intended for specialized use can be configured with management capabilities, which may defeat network isolation and security efforts. Ensure that only vmk interfaces intended for management have management services enabled.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Get-VMHostNetworkAdapter -VMHost $ESXi -Name $vmkernel_interface | Set-VMHostNetworkAdapter -ManagementTrafficEnabled $false

See Also

https://github.com/vmware/vcf-security-and-compliance-guidelines/raw/refs/heads/main/security-configuration-hardening-guide/vsphere/8.0/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8, CCI|CCI-002418

Plugin: VMware

Control ID: 7019f3a65b3c82365a95bbcd5ad3128d123c0f376bee4c94e0d1435f3f1006ee