STIGQter STIGQter: STIG Summary: VMware NSX-T SDN Controller Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 30 Mar 2022:

The NSX-T Controller cluster must be on separate physical hosts.

DISA Rule

SV-251735r810063_rule

Vulnerability Number

V-251735

Group Title

SRG-NET-000512-SDN-001050

Rule Version

TSDC-3X-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This fix must be performed in vCenter.

From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX-T Managers are deployed >> Configure >> Configuration >> VM/Host Rules.

Click "Add" to create a new rule.

Provide a name and select "Separate Virtual Machines" under Type.

Add the three NSX-T Manager virtual machines to the list and click "OK".

Check Contents

This check must be performed in vCenter.

From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX-T Managers are deployed >> Configure >> Configuration >> VM/Host Rules.

If the NSX-T Manager cluster does not have rules applied to it that separate the nodes onto different physical hosts, this is a finding.

Vulnerability Number

V-251735

Documentable

False

Rule Version

TSDC-3X-000020

Severity Override Guidance

This check must be performed in vCenter.

From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX-T Managers are deployed >> Configure >> Configuration >> VM/Host Rules.

If the NSX-T Manager cluster does not have rules applied to it that separate the nodes onto different physical hosts, this is a finding.

Check Content Reference

M

Target Key

5450