VCENTER-000009 - Connectivity between Update Manager and patch repositories must be restricted by an Update Manager Download Server

Information

Note: Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

Configure the Update Manager Server to use a separate Update Manager Download Server; the use of physical media to transfer updated files to the Update Manager server (air-gap model) must be enforced and documented with organization policies. Configure the Update Manager Download Server and enable the Download Service. Patches must not be directly accessible to the Update Manager Server application from the Internet.

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx

Item Details

References: CAT|III, CCI|CCI-000366, Group-ID|V-39549, Rule-ID|SV-51407r1_rule, STIG-ID|VCENTER-000009

Plugin: VMware

Control ID: a439fca35bb7fdc00513c64e810b7f8b04675aafdecee7455b2e3955045f1113