UCF STIG Viewer Logo

All dvPortgroup VLAN IDs must be fully documented.


Overview

Finding ID Version Rule ID IA Controls Severity
ESXI5-VMNET-000001 ESXI5-VMNET-000001 ESXI5-VMNET-000001_rule Low
Description
If using VLAN tagging on a dvPortgroup, tags must correspond to the IDs on external VLAN-aware upstream switches if any. If VLAN IDs are not tracked completely, mistaken re-use of IDs could allow for traffic to be allowed between inappropriate physical and virtual machines. Similarly, wrong or missing VLAN IDs may lead to traffic not passing between appropriate physical and virtual machines.
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-ESXI5-VMNET-000001_chk )
From the vSphere Client log into vCS. Home>> Inventory>> Networking. Select dvSwitch and dvPortgroup and "Edit Settings>> Policies>> VLAN>> VLAN ID". The dvPortGroup VLAN tags must be documented to match the IDs on external VLAN-aware upstream switches. Verify that VLAN IDs are documented and matched in an (organization-specific) tracking system. If the VLAN tagging on a dvPortgroup does not correspond to the IDs on external VLAN-aware upstream switches, this is a finding.
Fix Text (F-ESXI5-VMNET-000001_fix)
From the vSphere Client log into vCS. Home>> Inventory>> Networking. Select dvSwitch and dvPortgroup and "Edit Settings>> Policies>> VLAN>> VLAN ID". Record all VLAN IDs in an organization-defined tracking system.