Parameter | Description | vCenter | CurrentValue |
---|---|---|---|
vCenter.verify-nfc-ssl | Check Network File Copy NFC uses SSL | vcenter.lab.com | Not Set |
Parameter | Description | VMHost | vSwitch | CurrentValue |
---|---|---|---|---|
vNetwork.reject-forged-transmit | Ensure that the Forged Transmits policy is set to reject | esxi2.lab.com | vSwitch0 | Accept |
vNetwork.reject-mac-changes | Ensure that the MAC Address Changes policy is set to reject | esxi2.lab.com | vSwitch0 | Accept |
vNetwork.reject-promiscuous-mode | Ensure that the Promiscuous Mode policy is set to reject | esxi2.lab.com | vSwitch0 | Reject |
vNetwork.reject-forged-transmit | Ensure that the Forged Transmits policy is set to reject | esxi1.lab.com | vSwitch0 | Accept |
vNetwork.reject-mac-changes | Ensure that the MAC Address Changes policy is set to reject | esxi1.lab.com | vSwitch0 | Accept |
vNetwork.reject-promiscuous-mode | Ensure that the Promiscuous Mode policy is set to reject | esxi1.lab.com | vSwitch0 | Reject |
Parameter | Description | DVSwitch | Portgroup | CurrentValue |
---|---|---|---|---|
vNetwork.reject-mac-changes-dvportgroup | Ensure that the Mac Changes policy is set to reject | Cloud dvSwitch | Cloud dvSwitch-DVUplinks-881 | Reject |
vNetwork.reject-forged-transmit-dvportgroup | Ensure that the Forged Transmits policy is set to reject | Cloud dvSwitch | Cloud dvSwitch-DVUplinks-881 | Accept |
vNetwork.restrict-netflow-usage | Ensure that VDS Netflow traffic is only being sent to authorized collector IPs | Cloud dvSwitch | Cloud dvSwitch-DVUplinks-881 | Not Configured |
vNetwork.reject-mac-changes-dvportgroup | Ensure that the Mac Changes policy is set to reject | Cloud dvSwitch | Cloud-Port-Group | Reject |
vNetwork.reject-forged-transmit-dvportgroup | Ensure that the Forged Transmits policy is set to reject | Cloud dvSwitch | Cloud-Port-Group | Reject |
vNetwork.restrict-netflow-usage | Ensure that VDS Netflow traffic is only being sent to authorized collector IPs | Cloud dvSwitch | Cloud-Port-Group | Not Configured |
vNetwork.reject-mac-changes-dvportgroup | Ensure that the Mac Changes policy is set to reject | Cloud dvSwitch | Management Network | Reject |
vNetwork.reject-forged-transmit-dvportgroup | Ensure that the Forged Transmits policy is set to reject | Cloud dvSwitch | Management Network | Reject |
vNetwork.restrict-netflow-usage | Ensure that VDS Netflow traffic is only being sent to authorized collector IPs | Cloud dvSwitch | Management Network | Not Configured |
vNetwork.reject-mac-changes-dvportgroup | Ensure that the Mac Changes policy is set to reject | Cloud dvSwitch | vMotion | Reject |
vNetwork.reject-forged-transmit-dvportgroup | Ensure that the Forged Transmits policy is set to reject | Cloud dvSwitch | vMotion | Reject |
vNetwork.restrict-netflow-usage | Ensure that VDS Netflow traffic is only being sent to authorized collector IPs | Cloud dvSwitch | vMotion | Not Configured |
vNetwork.reject-mac-changes-dvportgroup | Ensure that the Mac Changes policy is set to reject | Cloud dvSwitch | VSAN | Reject |
vNetwork.reject-forged-transmit-dvportgroup | Ensure that the Forged Transmits policy is set to reject | Cloud dvSwitch | VSAN | Reject |
vNetwork.restrict-netflow-usage | Ensure that VDS Netflow traffic is only being sent to authorized collector IPs | Cloud dvSwitch | VSAN | Not Configured |
vNetwork.reject-mac-changes-dvportgroup | Ensure that the Mac Changes policy is set to reject | Cloud dvSwitch | FT | Reject |
vNetwork.reject-forged-transmit-dvportgroup | Ensure that the Forged Transmits policy is set to reject | Cloud dvSwitch | FT | Reject |
vNetwork.restrict-netflow-usage | Ensure that VDS Netflow traffic is only being sent to authorized collector IPs | Cloud dvSwitch | FT | Not Configured |
Parameter | Description | VMHost | LDUsers | Admin |
---|---|---|---|---|
ESXi.audit-exception-users | Audit the list of users who are on the Exception Users List and whether they have administrator privleges | esxi1.lab.com | No Locked Down User |
Parameter | Description | VMHost | Value |
---|---|---|---|
ESXi.config-snmp | Ensure proper SNMP configuration | esxi2.lab.com | Enabled |
ESXi.disable-mob | Disable Managed Object Browser (MOB) | esxi2.lab.com | Enabled |
ESXi.enable-ad-auth | Use Active Directory for local user authentication | esxi2.lab.com | AD not Configured |
ESXi.enable-auth-proxy | When adding ESXi hosts to Active Directory use the vSphere Authentication Proxy to protect passwords | esxi2.lab.com | Host Profile not Configured |
ESXi.enable-chap-auth | Enable bidirectional CHAP, also known as Mutual CHAP, authentication for iSCSI traffic | esxi2.lab.com | CHAP Authentication not Configured |
ESXi.enable-normal-lockdown-mode | Enable Normal Lockdown Mode to restrict access | esxi2.lab.com | Enabled |
ESXi.enable-remote-syslog | Configure remote logging for ESXi hosts | esxi2.lab.com | Syslog not Configured |
ESXi.enable-strict-lockdown-mode | Enable Strict lockdown mode to restrict access | esxi2.lab.com | lockdownDisabled |
ESXi.set-password-policies | Establish a password policy for password complexity | esxi2.lab.com | retry=3 min=disabled,disabled,disabled,7,7 |
ESXi.set-shell-interactive-timeout | Set a timeout to automatically terminate idle ESXi Shell and SSH sessions | esxi2.lab.com | Timeout Value not Configured |
ESXi.TransparentPageSharing-intra-enabled | Ensure default setting for intra-VM TPS is correct | esxi2.lab.com | Configured |
ESXi.config-ntp | Configure NTP time synchronization | esxi2.lab.com | 192.168.1.39 |
ESXi.config-persistent-logs | Configure persistent logging for all ESXi host | esxi2.lab.com | [] /scratch/log |
ESXi.verify-acceptance-level-accepted | Verify Image Profile and VIB Acceptance Levels | esxi2.lab.com | PartnerSupported |
vNetwork.verify-dvfilter-bind | Prevent unintended use of dvfilter network APIs | esxi2.lab.com | Not Set |
Parameter | Description | VMHost | Value |
---|---|---|---|
ESXi.config-snmp | Ensure proper SNMP configuration | esxi1.lab.com | Enabled |
ESXi.disable-mob | Disable Managed Object Browser (MOB) | esxi1.lab.com | Enabled |
ESXi.enable-ad-auth | Use Active Directory for local user authentication | esxi1.lab.com | AD not Configured |
ESXi.enable-auth-proxy | When adding ESXi hosts to Active Directory use the vSphere Authentication Proxy to protect passwords | esxi1.lab.com | Host Profile not Configured |
ESXi.enable-chap-auth | Enable bidirectional CHAP, also known as Mutual CHAP, authentication for iSCSI traffic | esxi1.lab.com | CHAP Authentication not Configured |
ESXi.enable-normal-lockdown-mode | Enable Normal Lockdown Mode to restrict access | esxi1.lab.com | Enabled |
ESXi.enable-remote-syslog | Configure remote logging for ESXi hosts | esxi1.lab.com | Syslog not Configured |
ESXi.enable-strict-lockdown-mode | Enable Strict lockdown mode to restrict access | esxi1.lab.com | lockdownDisabled |
ESXi.set-password-policies | Establish a password policy for password complexity | esxi1.lab.com | retry=3 min=disabled,disabled,disabled,7,7 |
ESXi.set-shell-interactive-timeout | Set a timeout to automatically terminate idle ESXi Shell and SSH sessions | esxi1.lab.com | Timeout Value not Configured |
ESXi.TransparentPageSharing-intra-enabled | Ensure default setting for intra-VM TPS is correct | esxi1.lab.com | Configured |
ESXi.config-ntp | Configure NTP time synchronization | esxi1.lab.com | 192.168.1.39 |
ESXi.config-persistent-logs | Configure persistent logging for all ESXi host | esxi1.lab.com | [] /scratch/log |
ESXi.verify-acceptance-level-accepted | Verify Image Profile and VIB Acceptance Levels | esxi1.lab.com | PartnerSupported |
vNetwork.verify-dvfilter-bind | Prevent unintended use of dvfilter network APIs | esxi1.lab.com | Not Set |
Parameter | Description | Name | Entity | Value |
---|---|---|---|---|
VM.disable-console-copy | Explicitly disable copy/paste operations | isolation.tools.copy.disable | Test-Template | Configured |
VM.disable-console-drag-n-drop | Explicitly disable copy/paste operations | isolation.tools.dnd.disable | Test-Template | Not Configured |
VM.disable-console-gui-options | Explicitly disable copy/paste operations | isolation.tools.setGUIOptions.enable | Test-Template | Not Configured |
VM.disable-console-paste | Explicitly disable copy/paste operations | isolation.tools.paste.disable | Test-Template | Not Configured |
VM.disable-disk-shrinking-shrink | Disable virtual disk shrinking | isolation.tools.diskShrink.disable | Test-Template | Not Configured |
VM.disable-disk-shrinking-wiper | Disable virtual disk shrinking | isolation.tools.diskWiper.disable | Test-Template | Not Configured |
VM.disable-hgfs | Disable HGFS file transfers | isolation.tools.hgfsServerSet.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-autologon | Disable certain unexposed features | isolation.tools.ghi.autologon.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-biosbbs | Disable certain unexposed features | isolation.bios.bbs.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-getcreds | Disable certain unexposed features | isolation.tools.getCreds.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-launchmenu | Disable certain unexposed features | isolation.tools.ghi.launchmenu.change | Test-Template | Not Configured |
VM.disable-unexposed-features-memsfss | Disable certain unexposed features | isolation.tools.memSchedFakeSampleStats.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-protocolhandler | Disable certain unexposed features | isolation.tools.ghi.protocolhandler.info.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-shellaction | Disable certain unexposed features | isolation.ghi.host.shellAction.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-toporequest | Disable certain unexposed features | isolation.tools.dispTopoRequest.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-trashfolderstate | Disable certain unexposed features | isolation.tools.trashFolderState.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-trayicon | Disable certain unexposed features | isolation.tools.ghi.trayicon.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-unity | Disable certain unexposed features | isolation.tools.unity.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-unity-interlock | Disable certain unexposed features | isolation.tools.unityInterlockOperation.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-unitypush | Disable certain unexposed features | isolation.tools.unity.push.update.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-unity-taskbar | Disable certain unexposed features | isolation.tools.unity.taskbar.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-unity-unityactive | Disable certain unexposed features | isolation.tools.unityActive.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-unity-windowcontents | Disable certain unexposed features | isolation.tools.unity.windowContents.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-versionget | Disable certain unexposed features | isolation.tools.vmxDnDVersionGet.disable | Test-Template | Not Configured |
VM.disable-unexposed-features-versionset | Disable certain unexposed features | isolation.tools.guestDnDVersionSet.disable | Test-Template | Not Configured |
VM.disable-vix-messages | Disable VIX messages from the VM | isolation.tools.vixMessage.disable | Test-Template | Not Configured |
VM.disable-VMtools-autoinstall | Disable tools auto install | isolation.tools.autoInstall.disable | Test-Template | Not Configured |
VM.limit-setinfo-size | Disable tools auto install | tools.setInfo.sizeLimit | Test-Template | Not Configured |
RemoteDisplay.vnc.enabled | Remote Display VNC enabled | RemoteDisplay.vnc.enabled | Test-Template | Not Configured |
VM.prevent-device-interaction-connect | Prevent unauthorized removal, connection and modification of devices | isolation.device.connectable.disable | Test-Template | Not Configured |
VM.prevent-device-interaction-edit | Prevent unauthorized removal, connection and modification of devices | isolation.device.edit.disable | Test-Template | Not Configured |
VM.restrict-host-info | Restrict Host Information | tools.guestlib.enableHostInfo | Test-Template | Not Configured |
VM.TransparentPageSharing-inter-VM-Enabled | List the VMs and their current settings | Mem.ShareForceSalting | Test-Template | Not Configured |
VM.verify-network-filter | List the VMs and their current settings | ethernet*.filter*.name* | Test-Template | Not Configured |
VM.verify-PCI-Passthrough | List the VMs and their current settings | pciPassthru*.present | Test-Template | Not Configured |
Parameter | Description | Name | Entity | Value |
---|---|---|---|---|
VM.disable-console-copy | Explicitly disable copy/paste operations | isolation.tools.copy.disable | vc-01 | Configured |
VM.disable-console-drag-n-drop | Explicitly disable copy/paste operations | isolation.tools.dnd.disable | vc-01 | Not Configured |
VM.disable-console-gui-options | Explicitly disable copy/paste operations | isolation.tools.setGUIOptions.enable | vc-01 | Not Configured |
VM.disable-console-paste | Explicitly disable copy/paste operations | isolation.tools.paste.disable | vc-01 | Not Configured |
VM.disable-disk-shrinking-shrink | Disable virtual disk shrinking | isolation.tools.diskShrink.disable | vc-01 | Not Configured |
VM.disable-disk-shrinking-wiper | Disable virtual disk shrinking | isolation.tools.diskWiper.disable | vc-01 | Not Configured |
VM.disable-hgfs | Disable HGFS file transfers | isolation.tools.hgfsServerSet.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-autologon | Disable certain unexposed features | isolation.tools.ghi.autologon.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-biosbbs | Disable certain unexposed features | isolation.bios.bbs.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-getcreds | Disable certain unexposed features | isolation.tools.getCreds.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-launchmenu | Disable certain unexposed features | isolation.tools.ghi.launchmenu.change | vc-01 | Not Configured |
VM.disable-unexposed-features-memsfss | Disable certain unexposed features | isolation.tools.memSchedFakeSampleStats.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-protocolhandler | Disable certain unexposed features | isolation.tools.ghi.protocolhandler.info.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-shellaction | Disable certain unexposed features | isolation.ghi.host.shellAction.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-toporequest | Disable certain unexposed features | isolation.tools.dispTopoRequest.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-trashfolderstate | Disable certain unexposed features | isolation.tools.trashFolderState.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-trayicon | Disable certain unexposed features | isolation.tools.ghi.trayicon.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-unity | Disable certain unexposed features | isolation.tools.unity.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-unity-interlock | Disable certain unexposed features | isolation.tools.unityInterlockOperation.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-unitypush | Disable certain unexposed features | isolation.tools.unity.push.update.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-unity-taskbar | Disable certain unexposed features | isolation.tools.unity.taskbar.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-unity-unityactive | Disable certain unexposed features | isolation.tools.unityActive.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-unity-windowcontents | Disable certain unexposed features | isolation.tools.unity.windowContents.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-versionget | Disable certain unexposed features | isolation.tools.vmxDnDVersionGet.disable | vc-01 | Not Configured |
VM.disable-unexposed-features-versionset | Disable certain unexposed features | isolation.tools.guestDnDVersionSet.disable | vc-01 | Not Configured |
VM.disable-vix-messages | Disable VIX messages from the VM | isolation.tools.vixMessage.disable | vc-01 | Not Configured |
VM.disable-VMtools-autoinstall | Disable tools auto install | isolation.tools.autoInstall.disable | vc-01 | Not Configured |
VM.limit-setinfo-size | Disable tools auto install | tools.setInfo.sizeLimit | vc-01 | Not Configured |
RemoteDisplay.vnc.enabled | Remote Display VNC enabled | RemoteDisplay.vnc.enabled | vc-01 | Not Configured |
VM.prevent-device-interaction-connect | Prevent unauthorized removal, connection and modification of devices | isolation.device.connectable.disable | vc-01 | Not Configured |
VM.prevent-device-interaction-edit | Prevent unauthorized removal, connection and modification of devices | isolation.device.edit.disable | vc-01 | Not Configured |
VM.restrict-host-info | Restrict Host Information | tools.guestlib.enableHostInfo | vc-01 | Not Configured |
VM.TransparentPageSharing-inter-VM-Enabled | List the VMs and their current settings | Mem.ShareForceSalting | vc-01 | Not Configured |
VM.verify-network-filter | List the VMs and their current settings | ethernet*.filter*.name* | vc-01 | Not Configured |
VM.verify-PCI-Passthrough | List the VMs and their current settings | pciPassthru*.present | vc-01 | Not Configured |