ESXi Firewall Disabled
Description
Detects the ESXi firewall being turned off or switched to a default allow. The firewall is the host filter for management services. Disabling it, or setting the default action to accept, lets later connections reach services that were previously blocked.
Query · kuery
data_stream.dataset:vsphere.log and message:("Firewall has been disabled" or "network firewall set" and ("--default-action true" or "--default-action=true" or "--enabled false" or "--enabled=false"))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Firewall changes are part of some network troubleshooting and product installs. Confirm the change was temporary and that `--enabled true` and a DROP default action were restored.
Analyst notes
Investigating ESXi Firewall Disabled
The ESXi firewall is the host filter for management services. Disabling it, or setting the default action to accept, lets later connections skip that control.
Possible investigation steps
- Read message to see whether the firewall was disabled or the default action was set to true.
- Check a later esxcli network firewall get or hostd message showing the firewall enabled again.
- Correlate with SSH enablement, syslog changes, and VM shutdown commands.
False positive analysis
A short troubleshooting window that turns the firewall off and back on can be benign. A disable that is still in effect, with no ticket, should be treated as hostile.
Response and remediation
- Re-enable the firewall and set the default action back to DROP: esxcli network firewall set --enabled true --default-action false.
- Review ruleset changes made in the same session.
- If the change was unauthorized, isolate the host and rotate credentials.