Virtual machines (VMs) must enable encryption for vMotion. (2024)

Virtual machines (VMs) must enable encryption for vMotion.


Overview

Finding ID Version Rule ID IA Controls Severity
V-258716 VMCH-80-000203 SV-258716r933209_rule Medium
Description
vMotion migrations in vSphere 6.0 and earlier transferred working memory and CPU state information in clear text over the vMotion network. As of vSphere 6.5, this transfer can be transparently encrypted using 256-bit AES-GCM with negligible performance impact.vSphere enables encrypted vMotion by default as "Opportunistic", meaning that encrypted channels are used where supported, but the operation will continue in plain text where encryption is not supported.For example, when vMotioning between two hosts, encryption will always be used. However, because 6.0 and earlier releases do not support this feature, vMotion from a 7.0 host to a 6.0 host would be allowed but would not be encrypted. If the encryption is set to "Required", vMotions to unsupported hosts will fail. This must be set to "Opportunistic" or "Required".
STIG Date
VMware vSphere 8.0 Virtual Machine Security Technical Implementation Guide 2023-10-11

Details

Check Text ( C-62456r933207_chk )
For each virtual machine do the following:

From the vSphere Client, right-click the Virtual Machine and go to Edit Settings >> VM Options >> Encryption.

or

From a PowerCLI command prompt while connected to the ESXi host or vCenter server, run the following command:

Get-VM | Where {($_.ExtensionData.Config.MigrateEncryption -eq "disabled")}

If the "Encrypted vMotion" setting does not have a value of "Opportunistic" or "Required", this is a finding.

Fix Text (F-62365r933208_fix)
For each virtual machine do the following:

From the vSphere Client, right-click the Virtual Machine and go to Edit Settings >> VM Options >> Encryption.

For "Encrypted vMotion" set the value to "Opportunistic" or "Required". Click "OK".

or

From a PowerCLI command prompt while connected to the ESXi host or vCenter server, run the following commands:

$spec = New-Object VMware.Vim.VirtualMachineConfigSpec
$spec.MigrateEncryption = New-Object VMware.Vim.VirtualMachineConfigSpecEncryptedVMotionModes
$spec.MigrateEncryption = $true
(Get-VM -Name

).ExtensionData.ReconfigVM($spec)
Virtual machines (VMs) must enable encryption for vMotion. (2024)
Top Articles
The Value of Mobile and Digital Wallets
How to open Google Wallet
Layla Deline Leaks
Alza Tutto Forklift
Wilson Tattoo Shops
Americanexpress.com/Myplatcard
Uworld Cost
Free Atm For Emerald Card Near Me
Nana Shirts Svg
Clever Sunny 540 - Wohnmobile Erlangen in Stuttgart
Becu Turbotax Discount Code
Indianapolis Star Obituary
Max Tl Nails
Ffxi Nasomi
Salmon Fest 2023 Lineup
SF bay area cars & trucks "chevrolet 50" - craigslist
Villanova University Common Data Set
Why Is There No Bottled Water In Supermarkets 2022
Ds Cuts Saugus
Pickapart Santa Fe Springs
Our Washes | Zips Car Wash
Megared Rewards
Montefiore Email Outlook Login
Ael Collegiate Essay Contest
Bevmo Monterey
Free Inter Tv Live
Bad Moms 123Movies
The Blackening Showtimes Near Regal Edwards Santa Maria & Rpx
Respiratory Syncytial Virus (RSV) Shot
Cbs Scores Mlb
Game Like Tales Of Androgyny
Robert Moses State Park ocean water temperature today | NY, United States temp
TheFanBus Free: The Ultimate Guide To Enjoying Your Favorite Events
Centricity Time And Attendance Premier Health
Brokensilenze Rupaul
Craigslist Rentals Coquille Oregon
Batting Cages Towson
Joliet's 2021 Captured In Photos By Patch
Costco Holiday Hours California
Young Snapchat Leaks
Chris Medlin: Credits, Bio, News & More | Broadway World
Creepshotorg
Craigs List Rochester
Pmrank 2022
Journal articles: 'History of journalistic criticism in Portugal' – Grafiati
Uihc Loop
St Edwards Bloomington Mn
Oklahoma Craigslist Pets
What Is The Factored Form Of The Polynomial 27X2Y-43Xy2
Bulletbound Codes
Harley Davidsons On Craigslist
Latest Posts
Article information

Author: Zonia Mosciski DO

Last Updated:

Views: 6146

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Zonia Mosciski DO

Birthday: 1996-05-16

Address: Suite 228 919 Deana Ford, Lake Meridithberg, NE 60017-4257

Phone: +2613987384138

Job: Chief Retail Officer

Hobby: Tai chi, Dowsing, Poi, Letterboxing, Watching movies, Video gaming, Singing

Introduction: My name is Zonia Mosciski DO, I am a enchanting, joyous, lovely, successful, hilarious, tender, outstanding person who loves writing and wants to share my knowledge and understanding with you.