1.6 Restrict port-level configuration overrides on vDS

Information

Restrict port-level configuration overrides on vDS.

*Rationale*

Port-level configuration over-rides are disabled by default. Once enabled, this allows for
different security settings to be set from what is established at the Port-Group level. There
are cases where particular VM's require unique configurations, but this should be
monitored so it is only used when authorized. If over-rides are not monitored, anyone who
gains access to a VM with a less secure VDS configuration could exploit that broader access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. From the Web or vSphere Clients.
2. Verify that Port Mirror destination interfaces are correct.
3. Edit the VDS properties and in the Port Mirror tab.
4. Configure the Destination VLAN, Port or Uplink ID's.

Default Value-Port-level configuration over-rides are disabled by default. This is the prescribed state.

See Also

https://workbench.cisecurity.org/files/902