SV-243120r719603_rule
V-243120
SRG-APP-000516
VCTR-67-000065
CAT II
10
From the vSphere Client, go to Hosts and Clusters >> select a vSAN Enabled Cluster >> Configure >> vSAN >> iSCSI Target Service.
For each iSCSI target, select the item and click "Edit".
Change the "Authentication" field to "Mutual CHAP" and configure the incoming and outgoing users and secrets appropriately.
If no clusters are enabled for vSAN or if vSAN is enabled but iSCSI is not enabled, this is not applicable.
From the vSphere Client, go to Hosts and Clusters >> select a vSAN Enabled Cluster >> Configure >> vSAN >> iSCSI Target Service.
For each iSCSI target, review the value in the "Authentication" column.
If the Authentication method is not set to "CHAP_Mutual" for any iSCSI target, this is a finding.
V-243120
False
VCTR-67-000065
If no clusters are enabled for vSAN or if vSAN is enabled but iSCSI is not enabled, this is not applicable.
From the vSphere Client, go to Hosts and Clusters >> select a vSAN Enabled Cluster >> Configure >> vSAN >> iSCSI Target Service.
For each iSCSI target, review the value in the "Authentication" column.
If the Authentication method is not set to "CHAP_Mutual" for any iSCSI target, this is a finding.
M
5399