Security Best Practices: Disabling Packet Forwarding on VMware ESXi
search cancel

Security Best Practices: Disabling Packet Forwarding on VMware ESXi

book

Article ID: 454806

calendar_today

Updated On:

Products

VMware vSphere ESX 8.x VMware vSphere ESX 7.x

Issue/Introduction

Review whether disabling packet forwarding is a recommended security hardening step for VMware ESXi environments.

Environment

VMware ESXi 7.0, 8.0 and later versions.

Resolution

Disabling packet forwarding is not a standard security best practice for ESXi. ESXi is an enterprise hypervisor designed for virtualization, not a general-purpose router. It does not possess a supported parameter to toggle "packet forwarding" as a hardening measure.

  1. Evaluate established security controls rather than attempting to modify unsupported kernel parameters.
  2. Enable Strict Lockdown Mode on the ESXi host to restrict direct access to the management interface.
  3. Audit and configure ESXi Firewall rules to limit access to essential services only.
  4. Implement Network Segregation to strictly separate management, vMotion, and data traffic at the virtual switch level.
  5. Refer to the vSphere Security Guide for official hardening requirements.

Additional Information

For further details on securing your environment, please refer to: