The vCenter Server must disable CDP/LLDP on distributed switches.
An XCCDF Rule
Description
The vSphere Distributed Virtual Switch can participate in Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP), as a listener, advertiser, or both. The information is sensitive, including IP addresses, system names, software versions, and more. It can be used by an adversary to gain a better understanding of your environment, and to impersonate devices. It is also transmitted unencrypted on the network, and as such the recommendation is to disable it.
- ID
- SV-258964r961863_rule
- Version
- VCSA-80-000299
- Severity
- Low
- References
- Updated
Remediation Templates
A Manual Procedure
From the vSphere Client, go to "Networking".
Select a distributed switch >> Configure >> Settings >> Properties.
Click "Edit".