ESXI-67-000066 - For physical switch ports connected to the ESXi host, the non-negotiate option must be configured for trunk links between external physical switches and virtual switches in Virtual Switch Tagging (VST) mode.

Information

To communicate with virtual switches in VST mode, external switch ports must be configured as trunk ports. VST mode does not support Dynamic Trunking Protocol (DTP), so the trunk must be static and unconditional. The auto or desirable physical switch settings do not work with the ESXi Server because the physical switch communicates with the ESXi Server using DTP.

The non-negotiate and on options unconditionally enable VLAN trunking on the physical switch and create a VLAN trunk link between the ESXi Server and the physical switch. The difference between non-negotiate and on options is that on mode still sends out DTP frames, whereas the non-negotiate option does not. The non-negotiate option should be used for all VLAN trunks to minimize unnecessary network traffic for virtual switches in VST mode.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Note that this check refers to an entity outside the physical scope of the ESXi server system.

Document the configuration of external switch ports as trunk ports.

Log in to the vendor-specific physical switch and disable DTP on the physical switch ports connected to the ESXi host.

Update the documentation according to an organization-defined frequency or whenever modifications are made to either ESXi hosts or the upstream external switch ports.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-239320r674889_rule, STIG-ID|ESXI-67-000066, Vuln-ID|V-239320

Plugin: VMware

Control ID: ab640f6b3184c78eda49f71a4ae84058c7b7910c462173919e26f6913766b466