STIGQter STIGQter: STIG Summary: VMware NSX-T Distributed Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Distributed Firewall must verify time-based firewall rules.

DISA Rule

SV-251733r810053_rule

Vulnerability Number

V-251733

Group Title

SRG-NET-000019-FW-000003

Rule Version

TDFW-3X-000042

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules.

Navigate to the offending Category and Policy section, click on the clock icon, then delete or modify the time window for that Policy. Click "Apply".

After all changes are made click "Publish".

Check Contents

From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules.

For each category, verify each Policy has no time windows configured or any existing time windows are expected. This can be viewed by clicking on the clock icon in each Policy section.

If there are unexpected or misconfigured time windows, this is a finding.

Vulnerability Number

V-251733

Documentable

False

Rule Version

TDFW-3X-000042

Severity Override Guidance

From the NSX-T Manager web interface, go to Security >> Distributed Firewall >> Category Specific Rules.

For each category, verify each Policy has no time windows configured or any existing time windows are expected. This can be viewed by clicking on the clock icon in each Policy section.

If there are unexpected or misconfigured time windows, this is a finding.

Check Content Reference

M

Target Key

5448