8.4.28 Ensure access to VM console via VNC protocol is limited

Information

Minimize access to the Virtual Machine via VNC protocol.

*Rationale*

The VM console enables you to connect to the console of a virtual machine, in effect seeing
what a monitor on a physical server would show. This console is also available via the VNC
protocol. Setting up this access also involves setting up firewall rules on each ESXi server
the virtual machine will run on.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs

Get-VM | New-AdvancedSetting -Name 'RemoteDisplay.vnc.enabled' -value $false

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: VMware

Control ID: 64c3f5227c2f996f5ef0b1a213e8e4af98456b573eb5cb534c6537f680d22752