STIGQter STIGQter: STIG Summary: VMware NSX-T Tier 1 Gateway RTR Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 30 Mar 2022:

The NSX-T Tier-1 Gateway must be configured to have the DHCP service disabled if not in use.

DISA Rule

SV-251771r810213_rule

Vulnerability Number

V-251771

Group Title

SRG-NET-000131-RTR-000035

Rule Version

T1RT-3X-000027

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to Networking >> Tier-1 Gateways and edit the target Tier-1 Gateway.

Click "Set DHCP Configuration", select "No Dynamic IP Address Allocation", click "Save", and then close "Editing".

Check Contents

From the NSX-T Manager web interface, go to Networking >> Tier-1 Gateways.

For every Tier-1 Gateway expand the Tier-1 Gateway to view the DHCP configuration.

If a DHCP profile is configured and not in use, this is a finding.

Vulnerability Number

V-251771

Documentable

False

Rule Version

T1RT-3X-000027

Severity Override Guidance

From the NSX-T Manager web interface, go to Networking >> Tier-1 Gateways.

For every Tier-1 Gateway expand the Tier-1 Gateway to view the DHCP configuration.

If a DHCP profile is configured and not in use, this is a finding.

Check Content Reference

M

Target Key

5454