Skip to content

The vCenter Server must disable CDP/LLDP on distributed switches.

An XCCDF Rule

Description

The vSphere Distributed Virtual Switch can participate in Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP), as a listener, advertiser, or both. The information is sensitive, including IP addresses, system names, software versions, and more. It can be used by an adversary to gain a better understanding of your environment, and to impersonate devices. It is also transmitted unencrypted on the network, and as such the recommendation is to disable it.

ID
SV-258964r961863_rule
Version
VCSA-80-000299
Severity
Low
References
Updated

Remediation Templates

A Manual Procedure

From the vSphere Client, go to "Networking".

Select a distributed switch >> Configure >> Settings >> Properties.

Click "Edit".