7.8 Ensure port-level configuration overrides are disabled.

Information

Port-level configuration overrides are disabled by default. Once enabled, it allows for different security to be set ignoring what is set at the Port-Group level.

Rationale:

There are cases where unique configurations are needed, but this should be monitored so it is only used when authorized. If overrides are not monitored, anyone who gains access to a VM with a less secure VDS configuration could secretly exploit the broader access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Using the vSphere Web Client,

For each portgroup within each distributed switch

Go to 'Configure' -> 'Settings' -> 'Properties'.

Click 'Edit'

Go to 'Advanced'.

Disable all 'Override port policies'.

See Also

https://workbench.cisecurity.org/benchmarks/8020

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2, CSCv7|12.4

Plugin: VMware

Control ID: 4160b2a86cf09a9e3941fb5b96c2600f44388f082c96b9d9cf37a0e6970ee998