STIGQter STIGQter: STIG Summary: VMware NSX 4.x Manager NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Managers must be deployed on separate physical hosts.

DISA Rule

SV-265359r994300_rule

Vulnerability Number

V-265359

Group Title

SRG-APP-000435-NDM-000315

Rule Version

NMGR-4X-000103

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This fix must be performed in vCenter.

From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX Managers are deployed >> Configure >> Configuration >> VM/Host Rules.

Click "Add" to create a new rule.

Provide a name and select "Separate Virtual Machines" under Type.

Add the three NSX Manager virtual machines to the list and click "OK".

Check Contents

This check must be performed in vCenter.

From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX Managers are deployed >> Configure >> Configuration >> VM/Host Rules.

If the NSX Manager cluster does not have rules applied to it that separate the nodes onto different physical hosts, this is a finding.

Vulnerability Number

V-265359

Documentable

False

Rule Version

NMGR-4X-000103

Severity Override Guidance

This check must be performed in vCenter.

From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX Managers are deployed >> Configure >> Configuration >> VM/Host Rules.

If the NSX Manager cluster does not have rules applied to it that separate the nodes onto different physical hosts, this is a finding.

Check Content Reference

M

Target Key

5633