The NSX-T Tier-1 Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
DISA Rule
SV-251740r810087_rule
Vulnerability Number
V-251740
Group Title
SRG-NET-000202-FW-000039
Rule Version
T0FW-3X-000021
Severity
CAT II
CCI(s)
- CCI-001097 - Monitor and control communications at the external managed interfaces to the system and at key managed interfaces within the system.
- CCI-001109 - Deny network communications traffic by default and allow network communications traffic by exception at managed interfaces; and/or for organization-defined systems.
- CCI-001190 - Fail to an organization-defined known-system state for the following failures on the indicated components while preserving organization-defined system state information in failure.
- CCI-001665 - Preserve organization-defined system state information in the event of a system failure.
Weight
10
Fix Recommendation
From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules. Choose each Tier-1 Gateway in drop-down, then select Policy_Default_Infra Section >> Action. Change the Action to "Drop" or "Reject", and then click "Publish".
Check Contents
From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules. Choose each Tier-1 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.
If the default_rule is set to "Allow", this is a finding.
Vulnerability Number
V-251740
Documentable
False
Rule Version
T0FW-3X-000021
Severity Override Guidance
From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules. Choose each Tier-1 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.
If the default_rule is set to "Allow", this is a finding.
Check Content Reference
M
Target Key
5451