ESXI5-VM-000051 - The system must control access to VMs through the dvfilter network APIs

Information

A VM must be configured explicitly to accept access by the dvfilter network API. This should be done only for VMs that are wanted to be done. An attacker might compromise the VM by making use of this introspection channel.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = ethernetn.filtern.name
keyval = <filtername>

See Also

http://iasecontent.disa.mil/stigs/zip/Jan2016/U_ESXi5_Virtual_Machine_V1R6_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-3, 800-53|CM-7, CAT|III, CCI|CCI-000366, Group-ID|V-39505, Rule-ID|SV-51363r1_rule, STIG-ID|ESXI5-VM-000051

Plugin: VMware

Control ID: dd0f5cee72eea44385cd7fbc7057069ad4f637e84a1883fdd713d9e85f5663cf