vNetwork : restrict-port-level-overrides

Information

Restrict port-level configuration overrides on VDS .
Port-level configuration overrides are disabled by default. Once enabled, this allows for different security settings to be set from what is established at the Port-Group level. There are cases where particular VM's require unique configurations, but this should be monitored so it is only used when authorized. If overrides are not monitored, anyone who gains access to a VM with a less secure VDS configuration could surreptiously exploit that broader access.

http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.security.doc/GUID-FA661AE0-C0B5-4522-951D-A3790DBE70B4.html

http://pubs.vmware.com/vsphere-60/topic/com.vmware.vsphere.networking.doc/GUID-DDF5CD98-454A-471D-9053-03ABB8FE86D1.html

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From vSphere Web Client, for each portgroup within each distributed switch go to "Manage" -> "Settings" -> "Properties". Click "Edit" and go to "Advanced". Disable all "Override port policies".

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vSphere_6_0_Hardening_Guide_GA_15_Jun_2015.xls