STIGQter STIGQter: STIG Summary: VMware NSX-T Tier-0 Gateway RTR Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Sep 2022:

The NSX-T Tier-0 Gateway must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.

DISA Rule

SV-251745r810119_rule

Vulnerability Number

V-251745

Group Title

SRG-NET-000019-RTR-000003

Rule Version

T0RT-3X-000013

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable multicast PIM routing on interfaces that are not required to support multicast by doing the following:

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways and expand the target Tier-0 gateway.

Expand "Interfaces", click on the number of interfaces present to open the interfaces dialog, and then select "Edit" on the target interface.

Expand "Multicast", change PIM to "disabled", and then click "Save".

Check Contents

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the Tier-0 Gateway >> Interfaces, and click on the number of interfaces present to open the interfaces dialog.

Expand each interface that is not required to support multicast routing, then expand "Multicast" and verify PIM is disabled.

If PIM is enabled on any interfaces that are not supporting multicast routing, this is a finding.

Vulnerability Number

V-251745

Documentable

False

Rule Version

T0RT-3X-000013

Severity Override Guidance

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the Tier-0 Gateway >> Interfaces, and click on the number of interfaces present to open the interfaces dialog.

Expand each interface that is not required to support multicast routing, then expand "Multicast" and verify PIM is disabled.

If PIM is enabled on any interfaces that are not supporting multicast routing, this is a finding.

Check Content Reference

M

Target Key

5452