STIGQter STIGQter: STIG Summary: VMware NSX-T Tier 1 Gateway RTR Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 30 Mar 2022:

The NSX-T Tier-1 Gateway must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.

DISA Rule

SV-251772r810216_rule

Vulnerability Number

V-251772

Group Title

SRG-NET-000193-RTR-000112

Rule Version

T1RT-3X-000034

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To create a segment QoS profile, do the following:

From the NSX-T Manager web interface, go to Networking >> Segments >> Segment Profiles.

Click "Add Segment Profile" and select "QoS".

Configure a profile name and QoS settings as needed and click "Save".

To apply a QoS profile to a segment do the following:

From the NSX-T Manager web interface, go to Networking >> Segments and edit the target segment.

Expand Segment Profiles and under QoS select the profile previously created and "Save".

Check Contents

From the NSX-T Manager web interface, go to Networking >> Segments.

For every Segment connected to a Tier-1 Gateway, Expand Segment >> Expand Segment Profiles >> Record QOS Segment Profile.

Go to Segment Profiles >> Expand QOS Segment Profile recorded in previous steps.

If there are traffic priorities specified by the Combatant Commands/Services/Agencies needed to ensure sufficient capacity for mission-critical traffic and none are configured, this is a finding.

Vulnerability Number

V-251772

Documentable

False

Rule Version

T1RT-3X-000034

Severity Override Guidance

From the NSX-T Manager web interface, go to Networking >> Segments.

For every Segment connected to a Tier-1 Gateway, Expand Segment >> Expand Segment Profiles >> Record QOS Segment Profile.

Go to Segment Profiles >> Expand QOS Segment Profile recorded in previous steps.

If there are traffic priorities specified by the Combatant Commands/Services/Agencies needed to ensure sufficient capacity for mission-critical traffic and none are configured, this is a finding.

Check Content Reference

M

Target Key

5454