STIGQter STIGQter: STIG Summary: VMware NSX-T Tier-0 Gateway RTR Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Sep 2022:

The NSX-T Tier-0 Gateway must be configured to use the BGP maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.

DISA Rule

SV-251756r856697_rule

Vulnerability Number

V-251756

Group Title

SRG-NET-000362-RTR-000117

Rule Version

T0RT-3X-000067

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To set maximum prefixes for BGP neighbors do the following:

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways and expand the target Tier-0 gateway.

Expand BGP. Next to BGP Neighbors, click on the number present to open the dialog, and then select "Edit" on the target BGP Neighbor.

Click "Router Filter", add or edit an existing router filter, enter a number for Maximum Routes, and then click "Add".

Click "Apply", then click "Save" to finish the configuration.

Check Contents

If the Tier-0 Gateway is not using BGP, this is Not Applicable.

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway with BGP enabled, expand the Tier-0 Gateway.

Expand BGP, click on the number next to BGP Neighbors, and then view the Router Filters for each neighbor.

If Maximum Routes is not configured or a route filter does not exist for each BGP neighbor, this is a finding.

Vulnerability Number

V-251756

Documentable

False

Rule Version

T0RT-3X-000067

Severity Override Guidance

If the Tier-0 Gateway is not using BGP, this is Not Applicable.

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway with BGP enabled, expand the Tier-0 Gateway.

Expand BGP, click on the number next to BGP Neighbors, and then view the Router Filters for each neighbor.

If Maximum Routes is not configured or a route filter does not exist for each BGP neighbor, this is a finding.

Check Content Reference

M

Target Key

5452