Skip to content

The vCenter Server must disable the distributed virtual switch health check.

An XCCDF Rule

Description

Network health check is disabled by default. Once enabled, the health check packets contain information on host#, vds#, and port#, which an attacker would find useful. It is recommended that network health check be used for troubleshooting and turned off when troubleshooting is finished.

ID
SV-258934r961863_rule
Version
VCSA-80-000267
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

From the vSphere Client, go to "Networking".

Select a distributed switch >> Configure >> Settings >> Health Check.

Click "Edit".