ESXi: esxi-8.iscsi-mutual-chap

Information

Enable bidirectional/mutual CHAP authentication for iSCSI traffic. Mutual CHAP provides an additional layer of protection by requiring both the initiator (client) and the target (server) to verify their identities to each other, thereby ensuring data transmitted between the two is not intercepted or altered by unauthorized entities.

Solution

Get-VMHost -Name $ESXi | Get-VMHostHba | Where {$_.Type -eq "Iscsi"} | Set-VMHostHba <parameters>

See Also

https://github.com/vmware/vcf-security-and-compliance-guidelines/raw/refs/heads/main/security-configuration-hardening-guide/vsphere/8.0/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-3(1), CCI|CCI-001967

Plugin: VMware

Control ID: a9138015322b68be3a4ef974dae44f52fdad472e6c3bde248913a3812ae16141