VCENTER-000009 - Connectivity between Update Manager and patch repositories must be restricted by an Update Manager Download Server

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the Update Manager Server to use a separate Update Manager Download Server; the use of physical media to transfer updated files to the Update Manager server (air-gap model) must be enforced and documented with organization policies. Configure the Update Manager Download Server and enable the Download Service. Patches must not be directly accessible to the Update Manager Server application from the Internet.

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|III, CCI|CCI-000366, Group-ID|V-39549, Rule-ID|SV-51407r1_rule, STIG-ID|VCENTER-000009, Vuln-ID|V-39549

Plugin: VMware

Control ID: a439fca35bb7fdc00513c64e810b7f8b04675aafdecee7455b2e3955045f1113