The NSX-T Distributed Firewall must generate traffic log entries containing information to establish the details of the event.
DISA Rule
SV-251727r810035_rule
Vulnerability Number
V-251727
Group Title
SRG-NET-000074-FW-000009
Rule Version
TDFW-3X-000005
Severity
CAT II
CCI(s)
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
Weight
10
Fix Recommendation
From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules.
For each rule that has logging disabled, click the gear icon, toggle the logging option to "Enable" and click "Apply".
or
For each Policy or Section, click the menu icon on the left and select "Enable Logging for All Rules".
After all changes are made, click "Publish".
Check Contents
From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> All Rules. For each rule, click the gear icon and verify the Logging setting.
If Logging is not enabled for any rule, this is a finding.
Vulnerability Number
V-251727
Documentable
False
Rule Version
TDFW-3X-000005
Severity Override Guidance
From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> All Rules. For each rule, click the gear icon and verify the Logging setting.
If Logging is not enabled for any rule, this is a finding.
Check Content Reference
M
Target Key
5448