1.5 Ensure that VDS Netflow traffic is only being sent to authorized collector IP Addresses

Information

Ensure that VDS Netflow traffic is only being sent to authorized collector IP Addresses.

*Rationale*

The vSphere vDS can export Netflow information about traffic crossing the vDS. Netflow
exports are not encrypted and can contain information about the virtual network making it
easier for a MITM attack to be executed successfully. If Netflow export is required, verify
that all vDS Netflow target IP Addresses are correct.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. From the Web or vSphere Clients.
2. Configure the Netflow destinations to be correct.
3. Edit the VDS properties.
4. In the Netflow tab, set the Collector Settings > IP Address and Port.

See Also

https://workbench.cisecurity.org/files/902