STIGQter STIGQter: STIG Summary: VMware NSX-T Tier-0 Gateway RTR Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Sep 2022:

Unicast Reverse Path Forwarding (uRPF) must be enabled on the NSX-T Tier-0 Gateway.

DISA Rule

SV-251750r810134_rule

Vulnerability Number

V-251750

Group Title

SRG-NET-000205-RTR-000014

Rule Version

T0RT-3X-000051

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Enable strict URPF mode on interfaces by doing the following:

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways and expand the target Tier-0 gateway.

Expand Interfaces, then click on the number of interfaces present to open the interfaces dialog. Select "Edit" on the target interface.

From the drop-down, set the URPF mode to "Strict" and then click "Save".

Check Contents

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway, expand Tier-0 Gateway >> Interfaces, and then click on the number of interfaces present to open the interfaces dialog.

Expand each interface to view the URPF Mode configuration.

If URPF Mode is not set to "Strict" on any interface, this is a finding.

Vulnerability Number

V-251750

Documentable

False

Rule Version

T0RT-3X-000051

Severity Override Guidance

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway, expand Tier-0 Gateway >> Interfaces, and then click on the number of interfaces present to open the interfaces dialog.

Expand each interface to view the URPF Mode configuration.

If URPF Mode is not set to "Strict" on any interface, this is a finding.

Check Content Reference

M

Target Key

5452