VMware Cloud Community
kwg66
Hot Shot
Hot Shot

VMCI hardening

The vSphere 5.5 u1 Security Hardening guide contains the disable-intervm-vmci configuration, it specifically states to  "Check virtual machine configuration settings and verify that vmci0.unrestricted is set to FALSE"

Well, in my 5.5 u2 environment this parameter doesn't exist within any VM.

All I see in the VMX file from top down regarding vmci is this:

vmci0.present = "TRUE"

vmci.filter.enable = "true"

vmci0.pciSlotNumber = "32"

vmci0.id = "799964382"

vmci0.present = "TRUE"

vmci.filter.enable = "true"

vmci0.pciSlotNumber = "32"

vmci0.id = "799964382"

Not sure why some of the same entries are presented more than once...  kind of ugly if you ask me.

I don't see any entry for vmci0.unrestricted, but the change type is MODIFY not ADD. 

So, is this just sloppy documentation by VMware's security team and the parameter vmci0.unrestricted actually needs to be added?

please advise on this feature.  I want to disable it in my PCI environment for better security. 

0 Kudos
0 Replies