STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-0 Gateway router must be configured to have routing protocols disabled if not in use.

DISA Rule

SV-265483r999918_rule

Vulnerability Number

V-265483

Group Title

SRG-NET-000131-RTR-000035

Rule Version

NT0R-4X-000106

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

If not used in the implementation, then disable BGP, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways and edit the target Tier-0 gateway.

Expand BGP, change from "On" to "Off", and then click "Save".

If not used in the implementation, then disable OSPF, do the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways and edit the target Tier-0 gateway.

Expand OSPF, change from "Enabled" to "Disabled", and then click "Save".

Check Contents

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the Tier-0 Gateway to view if border gateway protocol (BGP) or Open Shortest Path First (OSPF) is enabled.

If BGP and/or OSPF is enabled and not in use, this is a finding.

Vulnerability Number

V-265483

Documentable

False

Rule Version

NT0R-4X-000106

Severity Override Guidance

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-0 Gateways.

For every Tier-0 Gateway, expand the Tier-0 Gateway to view if border gateway protocol (BGP) or Open Shortest Path First (OSPF) is enabled.

If BGP and/or OSPF is enabled and not in use, this is a finding.

Check Content Reference

M

Target Key

5634