STIGQter STIGQter: STIG Summary: VMware NSX 4.x Manager NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Manager must be configured to synchronize internal information system clocks using redundant authoritative time sources.

DISA Rule

SV-265338r994237_rule

Vulnerability Number

V-265338

Group Title

SRG-APP-000373-NDM-000298

Rule Version

NMGR-4X-000067

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To configure a profile to apply NTP servers to all NSX Manager nodes, do the following:

From the NSX Manager web interface, go to System >> Configuration >> Fabric >> Profiles >> Node Profiles.

Click "All NSX Nodes" and then click "Edit".

Under NTP servers, remove any unknown or nonauthoritative NTP servers, enter at least two authoritative servers, and then click "Save".

or

From an NSX Manager shell, run the following commands:

> del ntp-server <server-ip or server-name>
> set ntp-server <server-ip or server-name>

Check Contents

From the NSX Manager web interface, go to System >> Configuration >> Fabric >> Profiles >> Node Profiles.

Click "All NSX Nodes" and verify the NTP servers listed.

or

From an NSX Manager shell, run the following command:

> get ntp-server

If the output does not contain at least two authoritative time sources, this is a finding.

If the output contains unknown or nonauthoritative time sources, this is a finding.

Vulnerability Number

V-265338

Documentable

False

Rule Version

NMGR-4X-000067

Severity Override Guidance

From the NSX Manager web interface, go to System >> Configuration >> Fabric >> Profiles >> Node Profiles.

Click "All NSX Nodes" and verify the NTP servers listed.

or

From an NSX Manager shell, run the following command:

> get ntp-server

If the output does not contain at least two authoritative time sources, this is a finding.

If the output contains unknown or nonauthoritative time sources, this is a finding.

Check Content Reference

M

Target Key

5633