Support policy for CIS Benchmark hardening in VMware NSX
search cancel

Support policy for CIS Benchmark hardening in VMware NSX

book

Article ID: 430321

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Questions arise regarding the application of CIS Linux benchmark hardening to the VMware NSX appliance operating system.
  • This often includes requests to modify file permissions, disable network protocols, or alter system daemons to meet internal security compliance documents.

Environment

VMware NSX

Cause

VMware NSX is distributed as a pre-packaged, purpose-built appliance. The underlying Ubuntu-based operating system is heavily customized and tightly coupled with NSX management and control plane services.

Resolution

Modifications to the VMware NSX Manager or Edge appliance operating system are not supported. Applying generic CIS Linux benchmarks can break critical dependencies between the OS and NSX software.

Observe the following guidelines:

  1. Do not change default file permissions.
  2. Do not disable internal network protocols unless explicitly documented in the NSX product guides.
  3. Do not alter system daemons or install third-party security agents.

Any configuration changes or modification on the VMware NSX appliances or Edge appliance operating system are not supported by Broadcom.