Jul 09 2020
- last edited on
Nov 29 2021
Within ASC and "Vulnerabilities in security configuration on your machines should be remediated" my AKS nodes are being reported as requiring remediation.
If I were to remediate these they'll just come back if I scale out/in or upgrade? Also, as these are AKS nodes, shouldn't they be excluded or be patched already?
Disable SMB V1 with Samba
Run AuditD service
IP forwarding should be disabled. (net.ipv4.ip_forward = 0)
Anyone else experienced this? Or remediated?
Jul 13 2020
According to Azure support this is by design and they don't have plans to change it, many other users have this issue too, apparently...
I've put it on Azure feedback if anyone wants to vote it up https://feedback.azure.com/forums/347535-azure-security-center/suggestions/40878643-vm-scale-sets-ma...