STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway router must be configured to use its loopback address as the source address for Internal Border Gateway Protocol (IBGP) peering sessions.

DISA Rule

SV-265468r994754_rule

Vulnerability Number

V-265468

Group Title

SRG-NET-000512-RTR-000001

Rule Version

NT0R-4X-000091

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

To configure a loopback interface, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways and expand the target Tier-0 gateway.

Expand interfaces and click "Add Interface".

Enter a name, select "Loopback" as the Type, enter an IP address, select an Edge Node for the interface, then click "Save".

Note: More than one loopback may need to be configured depending on the routing architecture.


To set the source address for BGP neighbors, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways >> expand the target Tier-0 gateway.

Expand BGP >> next to BGP Neighbors, click on the number present to open the dialog >> select "Edit" on the target BGP Neighbor.

Under Source Addresses, configure the source address with the loopback address and click "Save".

Check Contents

If the Tier-0 Gateway is not using iBGP, this is Not Applicable.

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway with BGP enabled, expand the Tier-0 Gateway.

Expand BGP, click on the number next to BGP Neighbors, then view the source address for each neighbor.

If the Source Address is not configured as the Tier-0 Gateway loopback address for the iBGP session, this is a finding.

Vulnerability Number

V-265468

Documentable

False

Rule Version

NT0R-4X-000091

Severity Override Guidance

If the Tier-0 Gateway is not using iBGP, this is Not Applicable.

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway with BGP enabled, expand the Tier-0 Gateway.

Expand BGP, click on the number next to BGP Neighbors, then view the source address for each neighbor.

If the Source Address is not configured as the Tier-0 Gateway loopback address for the iBGP session, this is a finding.

Check Content Reference

M

Target Key

5634