0

VMware Security Hardening Guides

VMware Security Hardening Guides

 

Security Hardening Guides provide prescriptive guidance for customers on how to deploy and operate VMware products in a secure manner. Guides for vSphere are provided in an easy to consume spreadsheet format, with rich metadata to allow for guideline classification and risk assessment. They also include script examples for enabling security automation. Comparison documents are provided that list changes in guidance in successive versions of the guide.

 

  • Disabled SSH and Shell/Bash access.
  • Enable strict lockdown mode on ESXi. If necessary add trusted users to the exception users list so you won’t get locked out of ESXi.
  • Configure NTP time synchronization
  • Configure persistent logging for all ESXi host
  • Disable Managed Object Browser (MOB)
  • Use Active Directory for local user authentication
  • Configure the ESXi host firewall to restrict access to services running on the host 
  • Set the time after which a locked account is automatically unlocked
  • Set the count of maximum failed login attempts before the account is locked out
  • Set DCUI.Access to allow trusted users to override lockdown mode
  • Audit DCUI timeout value
  • Establish a password policy for password complexity
  • Set a timeout to automatically terminate idle ESXi Shell and SSH sessions
  • Set a timeout to limit how long the ESXi Shell and SSH services are allowed to run
  • Ensure default setting for intra-VM TPS is correct
  • Verify Image Profile and VIB Acceptance Levels
  • Explicitly disable copy/paste operations
  • Explicitly disable copy/paste operations
  • Disable virtual disk shrinking
  • Disable virtual disk shrinking
  • Avoid using independent nonpersistent disks
  • Disable 3D features on Server and desktop virtual machines
  • Disconnect unauthorized devices
  • Disconnect unauthorized devices
  • Disconnect unauthorized devices 
  • Disable all but VGA mode on specific virtual machines
  • Limit informational messages from the VM to the VMX file
  • Control access to VM console via VNC protocol
  • Do not send host information to guests
  • Check for enablement of salted, VM’s that are sharing memory pages
  • Control access to VMs through the dvfilter network APIs
  • Audit all uses of PCI or PCIe passthrough functionality
  • Enable BPDU filter on the ESXi host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled
  • Enable VDS network healthcheck only if you need it
  • Ensure that the “Forged Transmits” policy is set to reject
  • Ensure that the “Forged Transmits” policy is set to reject
  • Ensure that the “MAC Address Changes” policy is set to reject
  • Ensure that the “MAC Address Changes” policy is set to reject
  • Ensure that the “Promiscuous Mode” policy is set to reject
  • Ensure that the “Promiscuous Mode” policy is set to reject
  • Ensure that VDS Netflow traffic is only being sent to authorized collector IPs
  • Restrict port-level configuration overrides on VDS 
  • Audit use of dvfilter network APIs

 

Ref: https://www.vmware.com/security/hardening-guides.html

Install UMDS and the Update Manager Utility on Windows

Install UMDS and the Update Manager Utility on Windows

When you install UMDS, the Update Manager Utility is silently installed on your system as an additional component.

Prerequisites

  • Verify that the machine on which you install UMDS has Internet access, so that UMDS can download upgrades, patch metadata, and patch binaries.
  • Uninstall any 6.5 or earlier instance of UMDS if it is installed on the machine. If such a version of UMDS is already installed, the installation wizard displays an error message and the installation cannot proceed.
  • Before you install UMDS, create a database instance and configure it. If you install UMDS on a 64-bit machine, you must configure a 64-bit DSN and test it from ODBC. The database privileges and preparation steps are the same as the ones used for Update Manager.
  • If you plan to use the bundled Microsoft SQL Server 2012 Express database, make sure that you install Microsoft Windows Installer version 4.5 (MSI 4.5) on your system.
  • UMDS and Update Manager must be installed on different machines.
  • To ensure optimal performance, install UMDS on a system with requirements same as the ones for the Update Manager server.
  • Update Manager installation requires installation of the Microsoft .NET framework 4.7. Consider the following before proceeding with the installation.
    • Installing Microsoft .NET framework 4.7 is not supported on Microsoft Windows Server 2008 Service Pack 2 64-bit.
    • Installing Microsoft .NET framework 4.7 might require you to install some additional Windows updates. Relevant links to the Windows updates are provided during the Microsoft .NET framework 4.7.
    • Installing Microsoft .NET framework 4.7 might require you to reboot your host operating system.
    • If you plan to install Update Manager server on the same Windows machine where vCenter Server runs (typical installation), the vCenter Server service might temporarily disconnect if the a reboot is invoked on the system by the .NET Microsoft .NET framework 4.7 installation.
    • After installing or upgrading the Microsoft .NET framework 4.7, follow the prompts of the Update Manager server or the UMDS installation wizards.

Procedure

  1. Mount the ISO image of the vCenter Server installer to the Windows virtual machine or physical server on which you want to install the vSphere Update Manager Download Service (UMDS).
  2. In the mounted directory, double-click the autorun.exe file of the VMware vCenter Installer, and select vSphere Update Manager > Download Service.
  3. (Optional) Select the option to Use Microsoft SQL Server 2012 Express as the embedded database, and click Install.Note:Skip this step only if you plan to use another supported Oracle or SQL Server database.If the Microsoft SQL Server 2012 Express is not present on your system from previous Update Manager installations, the installation wizard for the Microsoft SQL Server 2012 Express opens.
  4. Select the option to install the Microsoft .NET framework 4.7.Note:If you do not select to install Microsoft .NET framework 4.7, the Update Manager Download Service installation will fail with an error message.
  5. On the VMware vCenter Installer, click Install.The VMware vCenter Installer wizard remains open, and a language selection dialog box opens.
  6. Select the language for the vSphere Update Manager Download Service installer, and click OK.
  7. Depending on the database selection you made in the VMware vCenter Installer, perform one of the following steps:
    • If you selected to use embedded Microsoft SQL Server 2012, wait for the installation process of the Microsoft .NET framework 4.7 and the Microsoft SQL Server 2012 to complete, and from the VMware vCenter Installer, click Install again.The VMware vSphere Update Manager Download Service installer opens.
    • If you are using another supported database and did not select to use the embedded Microsoft SQL Server 2012, the VMware vSphere Update Manager Download Service installer opens, and you can proceed with next steps.
  8. (Optional) If the wizard prompts you, install the required items such as Windows Installer 4.5.This step is required only if Windows Installer 4.5 is not present on your machine and you must perform it the first time you install a vSphere 5.x product. After the system restarts, the installer starts again.
  9. Review the Welcome page and click Next.
  10. Read and accept the license agreement, and click Next.
  11. (Optional) Select the database, and click Next.If you selected to use the embedded Microsoft SQL Server 2012 Express database, the installation wizard skips this page.
    1. Use an existing supported database, by selecting your database from the list of DSNs. If the DSN does not use Windows NT authentication, enter the user name and password for the DSN and click Next.
    Important:The DSN must be a 64-bit DSN.
  12. Enter the Update Manager Download Service proxy settings and click Next.
  13. Select the Update Manager Download Service installation and patch download directories and click Next.If you do not want to use the default locations, you can click Change to browse to a different directory. You can select the patch store to be an existing download directory from a previous UMDS 6.0 or UMDS 6.5 installation and reuse the applicable downloaded updates in UMDS 6.7. After you associate an existing download directory with UMDS 6.7, you cannot use it with earlier UMDS versions.
  14. (Optional) In the warning message about the disk free space, click OK.
  15. Click Install to begin the installation.
  16. Click OK in the Warning message notifying you that .NET Framework 4.7 is not installed.The UMDS installer installs the prerequisite before the actual product installation.
  17. Click Finish.

Ref: https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.update_manager_utility.doc/GUID-6B166453-28A2-4F9D-9260-72F57BA21DA5.html

Troubleshooting VMware High Availability (HA) issues in VMware vCenter Server

Troubleshooting VMware High Availability (HA) issues in VMware vCenter Server

Place the ESXi host in Maintenance Mode.

2. Disable Lockdown Mode on all hosts in cluster.
3. Connect to the ESXi host with SSH session.
4. Run this command to find the list of VIBs installed on the ESXi host:

esxcli software vib list
esxcli software vib list | grep vmware-fdm

5. Run this command to remove the VIB after verifying the dependency:
esxcli software vib remove -n vibname

6. Run this command to remove FDM agent from the ESXi host:
esxcli software vib remove -n vmware-fdm

Search the log files for any error message: 

 /var/log/fdm.log or /var/run/log/fdm* (one log file for FDM operations)
 /var/log/fdm-installer.log (FDM agent installation log)

Note: Disable HA on Cluster level and reenable it. (Check if there is any FT then need to log a ticket with VMware).