Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-39299 | SRG-OS-99999-ESXI5-000143 | SV-51115r2_rule | Low |
Description |
---|
NFC (Network File Copy) is used to migrate or clone a VM between two ESXi hosts over the network. By default, SSL is used only for the authentication of the transfer, but SSL must also be enabled on the data transfer. Without this setting VM contents could potentially be sniffed if the management network is not adequately isolated and secured. |
STIG | Date |
---|---|
VMware ESXi Server 5.0 Security Technical Implementation Guide | 2016-02-10 |
Check Text ( C-46563r2_chk ) |
---|
NOTE: SSL for NFC is used for copying or migrating VMs between ESXi hosts via vCenter. If the host is a standalone unit (i.e., not managed by a vCenter Server), this check is not applicable. From the vSphere client select "Administration >> vCenter Server Settings >> Advanced Settings". Verify "config.nfc.useSSL" is set to true. If "config.nfc.useSSL" is set to false, this is a finding. |
Fix Text (F-44278r1_fix) |
---|
From the vSphere client select "Administration >> vCenter Server Settings >> Advanced Settings". Set "config.nfc.useSSL = true". |