STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.

DISA Rule

SV-265479r994787_rule

Vulnerability Number

V-265479

Group Title

SRG-NET-000512-RTR-000012

Rule Version

NT0R-4X-000102

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

To configure the Neighbor Discovery hop limit, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways >> edit the target Tier-0 gateway.

Expand Additional Settings and select an "ND Profile" from the drop down with a hop limit of 32 or more, then click "Close Editing".

Note: The default ND profile has a hop limit of 64 and cannot be edited. If required, create a new or edit another existing ND profile to use.

Check Contents

If IPv6 forwarding is not enabled, this is Not Applicable.

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand Tier-0 Gateway >>Additional Settings.

Click on the ND profile name to view the hop limit.

If the hop limit is not configured to at least 32, this is a finding.

Vulnerability Number

V-265479

Documentable

False

Rule Version

NT0R-4X-000102

Severity Override Guidance

If IPv6 forwarding is not enabled, this is Not Applicable.

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand Tier-0 Gateway >>Additional Settings.

Click on the ND profile name to view the hop limit.

If the hop limit is not configured to at least 32, this is a finding.

Check Content Reference

M

Target Key

5634