The hypervisor hardening policy helps you to limit users access to the hypervisor, configure remote system logging, time synchronization and configure the SNMP agent settings.
Note: You must have the System Manager role assigned to manage virtual machines access permissions.
Important! Verify that you configure the connection to the VMware vCenter Server before you complete this procedure. Also, create a PUPM endpoint for each hypervisor that you want to apply the hardening policies to.
Follow these steps:
The Security Groups Management page appears displaying the security groups on the VMware vCenter Server and the CA Access Control Server details.
CA Access Control Enterprise Management displays the security group details and members.
Important! Verify that the security group you select has at least one ESX server as a member of the group.
The Manage Security Group Hypervisor Hardening host group name page opens.
Specifies a description of the hardening policy.
Specifies to block remote access to the hypervisor.
Specifies that the local administrative control is disabled.
Specifies that the tech support mode is disabled.
Specifies the interval, in seconds, after which to disable the tech support mode.
(ESXi Only) Specifies the full pathname of the datastore where syslog logs messages.
Example: [storage1]/var/log/messages
Defines the remote syslog host name.
Defines the remote syslog host port number.
Specifies the NTP (Network Time Protocol) server name.
Specifies that SNMP configuration is enabled.
Defines the SNMP listening port number.
Specifies the name of the communities that has read-only access.
Example: snmp-server community public RO
Defines the SNMP traps target hostname, port and community.
Format: target_hostname@port/community
Example: SNMP_host@55222/comm
Specifies to disable the use of VMSafe Network API.
Defines the name of a hypervisor administrator account. CA Access Control for Virtual Environments uses this account to connect to the hypervisor.
CA Access Control Enterprise Management deploys the hardening policies to the group.
| Copyright © 2011 CA. All rights reserved. | Tell Technical Publications how we can improve this information |