STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway router must be configured to use encryption for Open Shortest Path First (OSPF) routing protocol authentication.

DISA Rule

SV-265406r994568_rule

Vulnerability Number

V-265406

Group Title

SRG-NET-000168-RTR-000077

Rule Version

NT0R-4X-000029

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

To set authentication for OSPF area definitions, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways, and expand the target Tier-0 gateway.

Expand "OSPF", click the number next to "Area Definition". Select "Edit" on the target OSPF Area Definition.

Change the Authentication drop-down to MD5, enter a Key ID and Password, and then click "Save".

Note: The MD5 password can have a maximum of 16 characters.

Check Contents

If the Tier-0 Gateway is not using OSPF, this is Not Applicable.

To verify OSPF areas are using authentication with encryption, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the "Tier-0 Gateway".

Expand "OSPF", click the number next to "Area Definition", and view the "Authentication" field for each area.

If OSPF area definitions do not have the "Authentication" field set to "MD5" and a "Key ID" and "Password" configured, this is a finding.

Vulnerability Number

V-265406

Documentable

False

Rule Version

NT0R-4X-000029

Severity Override Guidance

If the Tier-0 Gateway is not using OSPF, this is Not Applicable.

To verify OSPF areas are using authentication with encryption, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the "Tier-0 Gateway".

Expand "OSPF", click the number next to "Area Definition", and view the "Authentication" field for each area.

If OSPF area definitions do not have the "Authentication" field set to "MD5" and a "Key ID" and "Password" configured, this is a finding.

Check Content Reference

M

Target Key

5634