VMWare ESXi 5.0 Server STIG Version Comparison
VMWare ESXi 5.0 Server Security Technical Implementation Guide
Comparison
There are 30 differences between versions v1 r10 (Jan. 27, 2017) (the "left" version) and v2 r1 (Oct. 27, 2021) (the "right" version).
Check ESXI5-VMNET-000001 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
All dvPortgroup VLAN IDs must be fully documented.
Check Content
If a vNetwork Distributed Switch (vDS) is not configured, this is not applicable. From applicable. From the vSphere Client log into vCS. Home >> Inventory >> Networking. Select dvSwitch and dvPortgroup and Edit Settings >> Policies >> VLAN >> VLAN ID. The dvPortGroup VLAN tags must be documented to match the IDs on external VLAN-aware upstream switches. Verify that VLAN IDs are documented and matched in an (organization-specific) tracking system. system. If If the VLAN tagging on a dvPortgroup does not correspond to the IDs on external VLAN-aware upstream switches, this is a finding.
Discussion
If using VLAN tagging on a dvPortgroup, tags must correspond to the IDs on external VLAN-aware upstream switches if any. If VLAN IDs are not tracked completely, mistaken re-use of IDs could allow for traffic to be allowed between inappropriate physical and virtual machines. Similarly, wrong or missing VLAN IDs may lead to traffic not passing between appropriate physical and virtual machines.
Fix
From the vSphere Client log into vCS. Home >> Inventory >> Networking. Select dvSwitch and dvPortgroup and Edit Settings >> Policies >> VLAN >> VLAN ID. Record all VLAN IDs in an organization defined tracking system.