SV-251729r810041_rule
V-251729
SRG-NET-000202-FW-000039
TDFW-3X-000021
CAT III
10
From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule and change action to "Drop" or "Reject".
After all changes are made, click "Publish".
Note: Before enabling, ensure the necessary rules to whitelist approved traffic are created and published or this change may result in loss of communication for workloads.
From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.
If the Default Layer3 Rule is set to "ALLOW", this is a finding.
V-251729
False
TDFW-3X-000021
From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.
If the Default Layer3 Rule is set to "ALLOW", this is a finding.
M
5448