5.10 (L1) Host must restrict the use of Virtual Guest Tagging (VGT) on standard virtual switches

Information

When a port group is set to VLAN 4095 on standard virtual switches, it enables Virtual Guest Tagging (VGT), letting all network frames pass to the attached virtual machines (VMs) without altering the VLAN tags. This requires VMs to process VLAN information themselves via an 802.1Q driver. Only authorized and capable VMs should be allowed to use VGT to prevent potential network issues like denial of service or unauthorized VLAN traffic interaction.

Restricting VGT use helps maintain network security by ensuring controlled VLAN tag management. It mitigates risks associated with denial of service or unauthorized VLAN interactions, contributing to a stable network environment.

Solution

To set port groups to values other than 4095 and 0 unless VGT is required, perform the following:

- From the vSphere Web Client, select the host.
- Click Configure then expand Networking
- Select Virtual switches
- Expand the Standard vSwitch.
- View the topology diagram of the switch, which shows the various port groups associated with that switch.
- For each port group on the vSwitch, verify and record the VLAN IDs used.
- If a VLAN ID change is needed, click the name of the port group in the topology diagram of the virtual switch.
- Click the Edit settings option.
- In the Properties section, enter an appropriate name in the Network label field.
- In the VLAN ID dropdown select or type a new VLAN.
- Click OK

Impact:

Incorrect VGT configuration can lead to denial of service or unauthorized VLAN traffic interaction. Restricting VGT may require alternative configurations for VMs needing independent VLAN tag management, potentially affecting network operation.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2, CSCv7|12.4

Plugin: VMware

Control ID: 7f1cee64118e0d13d2b36d57e7e1ce1d41bccc6be8336bd738fd0e7d81adae42