2.2 Configure the ESXi host firewall to restrict access to services running on the host

Information

The ESXi Firewall is enabled by default and allows ping (ICMP) and communication with
DHCP/DNS clients. Confirm that access to services are only allowed by authorized
IP's/networks to protect from outside attacks.

*Rationale*

Unrestricted access to services running on an ESXi host can expose a host to outside attacks
and unauthorized access. Reduce the risk by configuring the ESXi firewall to only allow
access from authorized networks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To implement the recommended configuration state, run the following ESXi shell
command-# /etc/init.d/[SERVICE] STOP

Impact-Only systems in the IP whitelist/ACL will be able to connect to services on the ESXi server.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: VMware

Control ID: 53ffa2155e849fdc8be74809aff6d6d25a0efcd5d12c3717cebab0aa9b7c77f1