ESXI5-VMNET-000008 - All physical switch ports must be configured with spanning tree disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Due to the integration of the ESXi Server into the physical network, the physical network (switch) adaptors must have spanning tree disabled or portfast configured for external switches, because VMware virtual switches do not support STP. Virtual switch uplinks do not create loops within the physical switch network. If these are not set, potential performance and connectivity issues might arise.

Solution

Note that this check refers to an entity outside the scope of the ESXi-v5 server system. Document the upstream physical switch configuration for spanning tree protocol disablement and/or portfast configuration for all physical ports connected to ESXi hosts. Log in to the physical switch(es) and disable spanning tree protocol and/or configure portfast for all physical ports connected to ESXi hosts. Update the documentation on an organization-defined frequency or whenever modifications are made to either ESXi hosts or the upstream physical switches

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Server_V1R10_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Group-ID|V-39365, Rule-ID|SV-51223r1_rule, STIG-ID|ESXI5-VMNET-000008, Vuln-ID|V-39365

Plugin: VMware

Control ID: 103a7de763df4997d0d4003878777d211286ff7ff2a1436d4fb710c0bdc9e2a1