Security Best Practices for Securing vSAN
You must follow multiple best practices at all times when you operate your vSAN storage.
Best Practice | Description |
---|---|
vSAN must reserve space to complete internal maintenance operations. VMW-vSAN-00186 | vSAN Operations Reserve capacity setting helps ensure that vSAN always has sufficient free space to maintain the availability and reliability of the vSAN datastore and prevent potential data loss or service disruptions due to insufficient capacity during operations like policy changes. This configuration parameter can be altered while the cluster is operational. |
NFS file shares on vSAN File Services must be configured to restrict access. VMW-vSAN-00185 | When configuring an NFS file share the "Customize net access" option should be selected with a restrictive set of permissions configured. |
SMB file shares on vSAN File Services must accept only encrypted SMB authentication communications. VMW-vSAN-00187 | When configuring an SMB file share the Protocol Encryption option must be enabled. |