6.7

Table Of Contents
Isolate vMotion Trac
vMotion migration information is transmitted in plain text. Anyone with access to the network over which
this information flows can view it. Potential attackers can intercept vMotion traffic to obtain the memory
contents of a VM. They might also stage a MiTM attack in which the contents are modified during
migration.
Separate vMotion traffic from production traffic on an isolated network. Set up the network to be
nonroutable, that is, make sure that no layer-3 router is spanning this and other networks, to prevent
outside access to the network.
Use a dedicated VLAN on a common standard switch for the vMotion port group. Production (VM) traffic
can use the same standard switch if the vMotion port group’s VLAN is not used by production VMs.
Use Virtual Switches with the vSphere Network Appliance API
Only If Required
Do not configure your host to send network information to a virtual machine unless you are using
products that use the vSphere Network Appliance API (DvFilter). If the vSphere Network Appliance API is
enabled, an attacker might attempt to connect a virtual machine to the filter. This connection might
provide access to the network of other virtual machines on the host.
If you are using a product that uses this API, verify that the host is configured correctly. See the sections
on DvFilter in Developing and Deploying vSphere Solutions, vServices, and ESX Agents. If your host is
set up to use the API, make sure that the value of the Net.DVFilterBindIpAddress parameter matches
the product that uses the API.
Procedure
1 Log in to the vSphere Web Client.
2 Select the host and click Configure.
3 Under System, select Advanced System Settings.
4 Scroll down to Net.DVFilterBindIpAddress and verify that the parameter has an empty value.
The order of parameters is not strictly alphabetical. Type DVFilter in the Filter text box to display all
related parameters.
5 Verify the setting.
n
If you are not using DvFilter settings, make sure that the value is blank.
n
If you are using DvFilter settings, make sure that the value of the parameter is correct. The value
must match the value that the product that uses the DvFilter is using.
vSphere Security
VMware, Inc. 215