ESXI5-VMNET-000012 - All port groups must not be configured to VLAN values reserved by upstream physical switches

Information

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

As root, log in to the ESXi Shell and run the command to set the value to something other than the vendor-specific reserved value.
esxcli network vswitch standard portgroup set --portgroup-name=<name> --vlan-id=<non-default_id_number>
Re-enable Lockdown Mode on the host.

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Server_V1R10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-39369, Rule-ID|SV-51227r1_rule, STIG-ID|ESXI5-VMNET-000012, Vuln-ID|V-39369

Plugin: VMware

Control ID: e255aea5cef0c9b1b37a17404409bf5094e3afc07faaec01f0176d229dae40be