6.5

Table Of Contents
2 Ensure that the install tipc /bin/true line appears in this le.
3 Save the le and close it.
Secure Internet Packet Exchange Protocol
Prevent the Internetwork Packet Exchange (IPX) protocol from loading vRealize appliances by default.
Potential aackers could exploit this protocol to compromise your system.
Avoid loading the IPX protocol module unless it is absolutely necessary. IPX protocol is an obsolete
network-layer protocol. Binding this protocol to the network stack increases the aack surface of the host.
Unprivileged local processes might cause the system to dynamically load a protocol handler by using the
protocol to open a socket.
Procedure
1 Open the /etc/modprobe.conf.local le in a text editor.
2 Ensure that the line install ipx /bin/true appears in this le.
3 Save the le and close it.
Secure Appletalk Protocol
Prevent the Appletalk protocol from loading on vRealize appliances by default. Potential aackers might
exploit this protocol to compromise your system.
Avoid loading the Appletalk Protocol module unless it is absolutely necessary. Binding this protocol to the
network stack increases the aack surface of the host. Unprivileged local processes might cause the system
to dynamically load a protocol handler by using the protocol to open a socket.
Procedure
1 Open the /etc/modprobe.conf.local le in a text editor.
2 Ensure that the line install appletalk /bin/true appears in this le.
3 Save the le and close it.
Secure DECnet Protocol
Prevent the DECnet protocol from loading on your system by default. Potential aackers might exploit this
protocol to compromise your system.
Avoid loading the DECnet Protocol module unless it is absolutely necessary. Binding this protocol to the
network stack increases the aack surface of the host. Unprivileged local processes could cause the system
to dynamically load a protocol handler by using the protocol to open a socket.
Procedure
1 Open the DECnet Protocol /etc/modprobe.conf.local le in a text editor.
2 Ensure that the line install decnet /bin/true appears in this le.
3 Save the le and close it.
Secure Firewire Module
Prevent the Firewire module from loading on vRealize appliances by default. Potential aackers might
exploit this protocol to compromise your system.
Avoid loading the Firewire module unless it is absolutely necessary.
Chapter 3 Secure Configuration of vRealize Operations Manager
VMware, Inc. 31