STIGQter STIGQter: STIG Summary: VMware NSX-T Distributed Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Distributed Firewall must be configured to send traffic log entries to a central audit server for management and configuration of the traffic log entries.

DISA Rule

SV-251730r863248_rule

Vulnerability Number

V-251730

Group Title

SRG-NET-000333-FW-000014

Rule Version

TDFW-3X-000026

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change configuration of NSX-T Distributed Firewall to send traffic log entries to a central audit server for management and configuration of the traffic log entries.

Log in to vSphere vCenter https interface with credentials authorized for administration, navigate to Browse to the host in the vSphere Client inventory >> Configure >> System >> Advanced System Settings >> Edit >> Syslog.global.LogHost >> value >> ssl://hostName1:1514 >> OK.

Note: Configure the syslog or SNMP server to send an alert if the events server is unable to receive events from the NSX-T and also if denial-of-service (DoS) incidents are detected. This is true if the events server is STIG compliant.

Check Contents

Verify NSX-T Distributed Firewall is configured to send traffic log entries to a central audit server for management and configuration of the traffic log entries.

Log in to vSphere vCenter https interface with credentials authorized for administration. Navigate to Browse to the host in the vSphere Client inventory >> Configure >> System >> Advanced System Settings >> Edit >> Syslog.global.LogHost.

Verify a STIG compliant events server is configured.

If Syslog.global.LogHost is not configured with a STIG compliant events server, this is a finding.

Vulnerability Number

V-251730

Documentable

False

Rule Version

TDFW-3X-000026

Severity Override Guidance

Verify NSX-T Distributed Firewall is configured to send traffic log entries to a central audit server for management and configuration of the traffic log entries.

Log in to vSphere vCenter https interface with credentials authorized for administration. Navigate to Browse to the host in the vSphere Client inventory >> Configure >> System >> Advanced System Settings >> Edit >> Syslog.global.LogHost.

Verify a STIG compliant events server is configured.

If Syslog.global.LogHost is not configured with a STIG compliant events server, this is a finding.

Check Content Reference

M

Target Key

5448