STIGQter STIGQter: STIG Summary: VMware NSX 4.x Manager NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Manager must be configured as a cluster.

DISA Rule

SV-265358r994297_rule

Vulnerability Number

V-265358

Group Title

SRG-APP-000435-NDM-000315

Rule Version

NMGR-4X-000102

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To add additional NSX Manager appliances do the following:

From the NSX Manager web interface, go to System >> Configuration >> Appliances, and then click "Add NSX Appliance".

Supply the required information to add additional nodes as needed, up to three total.

To configure NSX with a cluster VIP or external load balancer, do the following:

From the NSX Manager web interface, go to System >> Configuration >> Appliances, and then click "Set Virtual IP", enter a VIP that is part of the same subnet as the other management nodes, and then click "Save".

To configure NSX with an external load balancer, setup an external load balancer with the following requirements:

- Configure the external load balancer to control traffic to the NSX Manager nodes.
- Configure the external load balancer to use the round robin method and configure source persistence for the load balancer's virtual IP.
- Create or import a signed certificate and apply the same certificate to all the NSX Manager nodes. The certificate must have the FQDN of the virtual IP and each of the nodes in the SAN.

Note: An external load balancer will not work with the NSX Manager VIP. Do not configure an NSX Manager VIP if using an external load balancer.

If the cluster status is not in a healthy state, identify the degraded component on the appliance and troubleshoot the issue with the error information provided.

Check Contents

From the NSX Manager web interface, go to System >> Configuration >> Appliances.

Verify three NSX Managers are deployed, a VIP or external load balancer is configured, and the cluster is in a healthy state.

If three NSX Managers are not deployed, a VIP or external load balancer is not configured, and the cluster is not in a healthy state, this is a finding.

Vulnerability Number

V-265358

Documentable

False

Rule Version

NMGR-4X-000102

Severity Override Guidance

From the NSX Manager web interface, go to System >> Configuration >> Appliances.

Verify three NSX Managers are deployed, a VIP or external load balancer is configured, and the cluster is in a healthy state.

If three NSX Managers are not deployed, a VIP or external load balancer is not configured, and the cluster is not in a healthy state, this is a finding.

Check Content Reference

M

Target Key

5633