VCTR-67-000019 - The vCenter Server must not configure VLAN Trunking unless Virtual Guest Tagging (VGT) is required and authorized.

Information

When a port group is set to VLAN Trunking, the vSwitch passes all network frames in the specified range to the attached VMs without modifying the VLAN tags. In vSphere, this is referred to as Virtual Guest Tagging (VGT).

The VM must process the VLAN information itself via an 802.1Q driver in the OS. VLAN Trunking must only be implemented if the attached VMs have been specifically authorized and are capable of managing VLAN tags themselves.

If VLAN Trunking is enabled inappropriately, it may cause denial of service or allow a VM to interact with traffic on an unauthorized VLAN.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Client, go to Networking >> select a distributed switch >> select a distributed port group >> Configure >> Settings >> Policies.

Click 'Edit'.

Click the 'VLAN' tab.

If 'VLAN trunking' is not authorized, remove it by setting 'VLAN type' to 'VLAN' and configure an appropriate VLAN ID. Click 'OK'.

If 'VLAN trunking' is authorized but the range is too broad, modify the range in the 'VLAN trunk range' field to the minimum necessary and authorized range. An example range would be '1,3-5,8'. Click 'OK'.

or

From a PowerCLI command prompt while connected to the vCenter server, run the following command to configure trunking:

Get-VDPortgroup 'Portgroup Name' | Set-VDVlanConfiguration -VlanTrunkRange '<VLAN Range(s) comma separated>'

or

Run this command to configure a single VLAN ID:

Get-VDPortgroup 'Portgroup Name' | Set-VDVlanConfiguration -VlanId '<New VLAN#>'

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-243087r879887_rule, STIG-ID|VCTR-67-000019, Vuln-ID|V-243087

Plugin: VMware

Control ID: fe8d2a623c53f053c356a40a01879f6f75f175948586d8814363a786bab4fe93