vNetwork : verify-dvfilter-bind

Information

Prevent unintended use of dvfilter network APIs.

If you are not using a product such as VMware NSX that make use of the dvfilter network API, the host should not be configured to send network information to a IP Address. If the API is enabled and the system running at the IP address referenced is compromised then there is potential for that system to provide unauthorized access to the network of other VMs on the host. If you are using a product that makes use of this API then verify that the host has been configured correctly.

http://pubs.vmware.com/vsphere-65/topic/com.vmware.vsphere.security.doc/GUID-CD0783C9-1734-4B9A-B821-ED17A77B0206.html

http://pubs.vmware.com/vsphere-65/topic/com.vmware.vsphere.ext_solutions.doc/GUID-6013E15D-92CE-4970-953C-ACCB36ADA8AD.html

Solution

From vSphere web client, select host and then click "Configure" -> "Settings" -> "System" -> "Advanced System settings". Filter for Net.DVFilterBindIpAddress to see the configured value. Click edit and set it to the desired value or to the IP address of the appropriate VM using dvfilter network APIs.

See Also

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/files/xls/vmware-6-5-update-1-security-configuration-guide.xlsx

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: VMware

Control ID: a0fa81af088cb24ea063d50682c8330a31e74425b80c6d763d09bef39b165493