VMware Cloud Community
savagea
Enthusiast
Enthusiast

Creating a Custom Template for ESXi Hardening

I'd like to run a compliance check on our virtual environment.  But I'd like to run it against our own internal hardening guidelines.  How can I make a custom template based on the ESXi hardening guidelines?

Reply
0 Kudos
5 Replies
GSViFX
Enthusiast
Enthusiast

It is probably easier and arguably better to use the vmware templates and add exceptions where the rules do not apply to your hardening. You may find that vCm is not able to query some of the settings you want to look at. Creating additional rules etc must use the options and values that VCM is collecting from vcenter and in the specific views that are held within the product.

Sent from my phone, please excuse mistakes and short replies.

Reply
0 Kudos
savagea
Enthusiast
Enthusiast

Ok, but how do I go about doing this...  adding exceptions to existing vmware templates?  Thanks!

Reply
0 Kudos
firestartah
Virtuoso
Virtuoso

Procedure

1. Click Compliance.

2. Select Virtual Environment Compliance > Templates > template name.

3. Select the noncompliant result on which you are basing the exception and click Add Exception.

In this example, the noncompliant result is the RHEL_60_ProdDev guest machine.

4. Type the Name, Short Description, Description, and Sponsor in the text boxes and click Next.

5. Select the template to which you are applying the exception in the drop-down menu and click Next.

For this example, select Tools Running Not vCenter_Dev.

6. Select the object group to which you are applying the exception and click Next.

For this example, select All Virtual Objects.

7. Select the override options and the expiration date.

  • Select Override non-compliant results to compliant.
  • Select No Expiration.
  • Click Next.

8. To define the exception values, modify, delete, or add to the properties, operators, and values for the

selected results.

In this example, you are specifying the RHEL_60_ProdDev as the exception.

  • Click Add.
  • In the properties drop-down menu, select Object.
  • Select = as the rule operator.
  • Click the ellipsis button and select RHEL_60_ProdDev in the property values dialog box and click

OK.

  • Click Finish.
If you found this or other information useful, please consider awarding points for "Correct" or "Helpful". Gregg http://thesaffageek.co.uk
Reply
0 Kudos
firestartah
Virtuoso
Virtuoso

page 64 of the VCM admin guide

If you found this or other information useful, please consider awarding points for "Correct" or "Helpful". Gregg http://thesaffageek.co.uk
Reply
0 Kudos
GSViFX
Enthusiast
Enthusiast

Thanks firestartah, I missed the request to explain how to do it but looks like you have saved me the time. This is how I would do it.

The only thing to add is that you must select the template and click run template to get the non compliant result first.

Thanks

Sent from my phone, please excuse mistakes and short replies.

Reply
0 Kudos