STIGQter STIGQter: STIG Summary: VMware NSX-T Manager NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Manager must be configured to synchronize internal information system clocks using redundant authoritative time sources.

DISA Rule

SV-251782r879746_rule

Vulnerability Number

V-251782

Group Title

SRG-APP-000373-NDM-000298

Rule Version

TNDM-3X-000068

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure a profile to apply NTP servers to all NSX-T Manager nodes, do the following:

From the NSX-T Manager web interface, go to System >> Fabric >> Profiles >> Node Profiles. Click "All NSX Nodes" and then click "Edit".

Under NTP servers, remove any unknown or non-authoritative NTP servers, enter at least two authoritative servers, and then click "Save".

or

From an NSX-T Manager shell, run the following command(s):

> del ntp-server <server-ip or server-name>
> set ntp-server <server-ip or server-name>

Check Contents

From the NSX-T Manager web interface, go to System >> Fabric >> Profiles >> Node Profiles. Click "All NSX Nodes" and verify the NTP servers listed.

or

From an NSX-T Manager shell, run the following command(s):

> get ntp-server

If the output does not contain at least two authoritative time sources, this is a finding.

If the output contains unknown or non-authoritative time sources, this is a finding.

Vulnerability Number

V-251782

Documentable

False

Rule Version

TNDM-3X-000068

Severity Override Guidance

From the NSX-T Manager web interface, go to System >> Fabric >> Profiles >> Node Profiles. Click "All NSX Nodes" and verify the NTP servers listed.

or

From an NSX-T Manager shell, run the following command(s):

> get ntp-server

If the output does not contain at least two authoritative time sources, this is a finding.

If the output contains unknown or non-authoritative time sources, this is a finding.

Check Content Reference

M

Target Key

5449