STIGQter STIGQter: STIG Summary: VMware NSX-T Tier-0 Gateway RTR Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Sep 2022:

The NSX-T Tier-0 Gateway must be configured to have multicast disabled if not in use.

DISA Rule

SV-251759r810161_rule

Vulnerability Number

V-251759

Group Title

SRG-NET-000131-RTR-000035

Rule Version

T0RT-3X-000096

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

To disable Multicast do the following:

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways and edit the target Tier-0 Gateway.

Expand Multicast, change from "Enabled" to "Disabled", and then click "Save".

Check Contents

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the Tier-0 Gateway, then expand Multicast to view the Multicast configuration.

If Multicast is enabled and not in use, this is a finding.

Vulnerability Number

V-251759

Documentable

False

Rule Version

T0RT-3X-000096

Severity Override Guidance

From the NSX-T Manager web interface, go to Networking >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the Tier-0 Gateway, then expand Multicast to view the Multicast configuration.

If Multicast is enabled and not in use, this is a finding.

Check Content Reference

M

Target Key

5452