STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field by enabling Unicast Reverse Path Forwarding (uRPF).

DISA Rule

SV-265428r994634_rule

Vulnerability Number

V-265428

Group Title

SRG-NET-000205-RTR-000014

Rule Version

NT0R-4X-000051

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Enable strict URPF mode on interfaces by doing the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways and expand the target Tier-0 gateway.

Expand "Interfaces and GRE Tunnels", click on the number of interfaces present to open the interfaces dialog, and then select "Edit" on the target interface.

From the drop-down, set the URPF mode to "Strict" and then click "Save".

Check Contents

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand Tier-0 Gateway >> Interfaces and GRE Tunnels, and then click on the number of interfaces present to open the interfaces dialog.

Expand each interface to view the URPF Mode configuration.

If URPF Mode is not set to "Strict" on any interface, this is a finding.

Vulnerability Number

V-265428

Documentable

False

Rule Version

NT0R-4X-000051

Severity Override Guidance

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand Tier-0 Gateway >> Interfaces and GRE Tunnels, and then click on the number of interfaces present to open the interfaces dialog.

Expand each interface to view the URPF Mode configuration.

If URPF Mode is not set to "Strict" on any interface, this is a finding.

Check Content Reference

M

Target Key

5634