Information
The ESXi Firewall is enabled by default and allows ping (ICMP) and communication with
DHCP/DNS clients. Confirm that access to services are only allowed by authorized
IP's/networks to protect from outside attacks.
*Rationale*
Unrestricted access to services running on an ESXi host can expose a host to outside attacks
and unauthorized access. Reduce the risk by configuring the ESXi firewall to only allow
access from authorized networks.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To implement the recommended configuration state, run the following ESXi shell
command-# /etc/init.d/[SERVICE] STOP
Impact-Only systems in the IP whitelist/ACL will be able to connect to services on the ESXi server.
Default Value-The prescribed state is not the default state.