vNetwork : reject-promiscuous-mode - 'vswitch'

Information

Ensure that the Promiscuous Mode policy is set to reject.
When promiscuous mode is enabled for a virtual switch all virtual machines connected to the Portgroup have the potential of reading all packets across that network, meaning only the virtual machines connected to that Portgroup. Promiscuous mode is disabled by default on the ESXI Server, and this is the recommended setting. However, there might be a legitimate reason to enable it for debugging, monitoring or troubleshooting reasons. Security devices might require the ability to see all packets on a vSwitch. An exception should be made for the Portgroups that these applications are connected to, in order to allow for full-time visibility to the traffic on that Portgroup. Promiscous mode can be set at the vSwitch and/or the Portgroup level. You can override switch level settings at the Portgroup level.
http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.security.doc/GUID-92F3AB1F-B4C5-4F25-A010-8820D7250350.html

Solution

From the vSphere Web Client select the host and click "Manage" -> "Networking" -> "Virtual Switches". For each virtual switch and for each port group within that virtual switch, click Edit. Go to "Security" and set the "Promiscuous Mode" to "Reject".

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vSphere_6_0_Hardening_Guide_GA_15_Jun_2015.xls

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: VMware

Control ID: 43eb2ca65fcb6675d9b103755fd200fbd7eae8261ad2a79b38f8011a1ef2a218