STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception.

DISA Rule

SV-265368r994347_rule

Vulnerability Number

V-265368

Group Title

SRG-NET-000202-FW-000039

Rule Version

NT0F-4X-000016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

Choose each Tier-0 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.

Change the Action to "Drop" or "Reject", and then click "Publish".

Check Contents

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

Choose each Tier-0 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.

If the default_rule is set to "Allow", this is a finding.

Vulnerability Number

V-265368

Documentable

False

Rule Version

NT0F-4X-000016

Severity Override Guidance

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

Choose each Tier-0 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.

If the default_rule is set to "Allow", this is a finding.

Check Content Reference

M

Target Key

5631