STIGQter STIGQter: STIG Summary: VMware NSX-T Tier-0 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Tier-0 Gateway Firewall must generate traffic log entries containing information to establish the details of the event.

DISA Rule

SV-251737r810078_rule

Vulnerability Number

V-251737

Group Title

SRG-NET-000074-FW-000009

Rule Version

T0FW-3X-000006

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-0 Gateway and for each rule with logging disabled, click the gear icon, enable Logging, and then click "Apply".

After all changes are made, click "Publish".

Check Contents

If the Tier-0 Gateway is deployed in an Active/Active HA mode and no stateless rules exist, this is Not Applicable.

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-0 Gateway and for each rule, click the gear icon and verify the Logging setting.

If Logging is not Enabled, this is a finding.

Vulnerability Number

V-251737

Documentable

False

Rule Version

T0FW-3X-000006

Severity Override Guidance

If the Tier-0 Gateway is deployed in an Active/Active HA mode and no stateless rules exist, this is Not Applicable.

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-0 Gateway and for each rule, click the gear icon and verify the Logging setting.

If Logging is not Enabled, this is a finding.

Check Content Reference

M

Target Key

5451