Skip to content

The ESXi host must configure the firewall to restrict access to services running on the host.

An XCCDF Rule

Description

Unrestricted access to services running on an ESXi host can expose a host to outside attacks and unauthorized access. Reduce the risk by configuring the ESXi firewall to only allow access from authorized networks.

ID
SV-258794r1003574_rule
Version
ESXI-80-000239
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Firewall.

Click "Edit...". For each user-configurable enabled service, uncheck the check box to "Allow connections from any IP address" and input the site-specific network(s) required.