STIGQter STIGQter: STIG Summary: VMware NSX-T Tier 1 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Tier-1 Gateway Firewall must generate traffic log entries containing information to establish what type of events occurred.

DISA Rule

SV-251761r810178_rule

Vulnerability Number

V-251761

Group Title

SRG-NET-000074-FW-000009

Rule Version

T1FW-3X-000005

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and for each rule with logging disabled, click the gear icon and enable Logging, then click "Apply".

After all changes are made, click "Publish".

Check Contents

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and for each rule, click the gear icon and verify the Logging setting.

If Logging is not "Enabled", this is a finding.

Vulnerability Number

V-251761

Documentable

False

Rule Version

T1FW-3X-000005

Severity Override Guidance

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and for each rule, click the gear icon and verify the Logging setting.

If Logging is not "Enabled", this is a finding.

Check Content Reference

M

Target Key

5453