STIGQter STIGQter: STIG Summary: VMware NSX-T Tier 1 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Tier-1 Gateway Firewall must generate traffic log entries containing information to establish the details of the event.

DISA Rule

SV-251762r919235_rule

Vulnerability Number

V-251762

Group Title

SRG-NET-000075-FW-000010

Rule Version

T1FW-3X-000006

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and for each rule with logging disabled, click the gear icon and enable Logging and then click "Apply".

After all changes are made, click "Publish".

Check Contents

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and for each rule, click the gear icon and verify the Logging setting.

If Logging is not "Enabled", this is a finding.

Vulnerability Number

V-251762

Documentable

False

Rule Version

T1FW-3X-000006

Severity Override Guidance

From the NSX-T Manager web interface, go to Security >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and for each rule, click the gear icon and verify the Logging setting.

If Logging is not "Enabled", this is a finding.

Check Content Reference

M

Target Key

5453