STIGQter STIGQter: STIG Summary: VMware NSX-T Distributed Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Distributed Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

DISA Rule

SV-251729r810041_rule

Vulnerability Number

V-251729

Group Title

SRG-NET-000202-FW-000039

Rule Version

TDFW-3X-000021

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule and change action to "Drop" or "Reject".

After all changes are made, click "Publish".

Note: Before enabling, ensure the necessary rules to whitelist approved traffic are created and published or this change may result in loss of communication for workloads.

Check Contents

From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.

If the Default Layer3 Rule is set to "ALLOW", this is a finding.

Vulnerability Number

V-251729

Documentable

False

Rule Version

TDFW-3X-000021

Severity Override Guidance

From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.

If the Default Layer3 Rule is set to "ALLOW", this is a finding.

Check Content Reference

M

Target Key

5448