The NSX Tier-0 Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception.
DISA Rule
SV-265368r994347_rule
Vulnerability Number
V-265368
Group Title
SRG-NET-000202-FW-000039
Rule Version
NT0F-4X-000016
Severity
CAT II
CCI(s)
- CCI-001109 - Deny network communications traffic by default and allow network communications traffic by exception at managed interfaces; and/or for organization-defined systems.
- CCI-001097 - Monitor and control communications at the external managed interfaces to the system and at key managed interfaces within the system.
- CCI-001190 - Fail to an organization-defined known-system state for the following failures on the indicated components while preserving organization-defined system state information in failure.
- CCI-002403 - Only allow incoming communications from organization-defined authorized sources routed to organization-defined authorized destinations.
Weight
10
Fix Recommendation
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
Choose each Tier-0 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.
Change the Action to "Drop" or "Reject", and then click "Publish".
Check Contents
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
Choose each Tier-0 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.
If the default_rule is set to "Allow", this is a finding.
Vulnerability Number
V-265368
Documentable
False
Rule Version
NT0F-4X-000016
Severity Override Guidance
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
Choose each Tier-0 Gateway in drop-down, then select Policy_Default_Infra Section >> Action.
If the default_rule is set to "Allow", this is a finding.
Check Content Reference
M
Target Key
5631