STIGQter STIGQter: STIG Summary: VMware NSX-T Tier-0 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Tier-1 Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

DISA Rule

SV-251740r810087_rule

Vulnerability Number

V-251740

Group Title

SRG-NET-000202-FW-000039

Rule Version

T0FW-3X-000021

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules. Choose each Tier-1 Gateway in drop-down, then select Policy_Default_Infra Section >> Action. Change the Action to "Drop" or "Reject", and then click "Publish".

Check Contents

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules. Choose each Tier-1 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.

If the default_rule is set to "Allow", this is a finding.

Vulnerability Number

V-251740

Documentable

False

Rule Version

T0FW-3X-000021

Severity Override Guidance

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules. Choose each Tier-1 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.

If the default_rule is set to "Allow", this is a finding.

Check Content Reference

M

Target Key

5451