VCENTER-000034 - The Update Manager must not directly connect to public patch repositories on the Internet

Information

In a typical deployment, the Update Manager connects to public patch repositories on the Internet to download patches. This connection must be limited as much as possible to prevent access from the outside to the Update Manager system. Any channel to the Internet represents a threat.

Solution

To configure a Web server or local disk repository as a download source, from the vSphere Client/vCenter Server system, click Update Manager under Solutions and Applications. On the Configuration tab, under Settings, click Download Settings. In the Download Sources pane, select Use a shared repository. Enter the <site-specific> path or the URL to the shared repository. Click Validate URL to validate the path. Click Apply

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-39569, Rule-ID|SV-51427r1_rule, STIG-ID|VCENTER-000034, Vuln-ID|V-39569

Plugin: VMware

Control ID: b635ea47de182c33d28fecee676c72b2be976c0ad3436aeae2df4f0863c73827