STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway Firewall must generate traffic log entries.

DISA Rule

SV-265362r994329_rule

Vulnerability Number

V-265362

Group Title

SRG-NET-000074-FW-000009

Rule Version

NT0F-4X-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-0 Gateway and for each rule with logging disabled, click the gear icon, enable logging, and then click "Apply".

After all changes are made, click "Publish".

Check Contents

If the Tier-0 Gateway is deployed in an Active/Active HA mode and no stateless rules exist, this is Not Applicable.

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-0 Gateway and for each rule, click the gear icon and verify the logging setting.

If logging is not enabled, this is a finding.

Vulnerability Number

V-265362

Documentable

False

Rule Version

NT0F-4X-000004

Severity Override Guidance

If the Tier-0 Gateway is deployed in an Active/Active HA mode and no stateless rules exist, this is Not Applicable.

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-0 Gateway and for each rule, click the gear icon and verify the logging setting.

If logging is not enabled, this is a finding.

Check Content Reference

M

Target Key

5631