The NSX Tier-1 Gateway firewall must generate traffic log entries.
DISA Rule
SV-265488r994833_rule
Vulnerability Number
V-265488
Group Title
SRG-NET-000074-FW-000009
Rule Version
NT1F-4X-000004
Severity
CAT II
CCI(s)
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000067 - Employ automated mechanisms to monitor remote access methods.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
Weight
10
Fix Recommendation
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
For each Tier-1 Gateway and for each rule with logging disabled, click the gear icon and enable logging, and then click "Apply".
After all changes are made, click "Publish".
Check Contents
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
For each Tier-1 Gateway and for each rule, click the gear icon and verify the logging setting.
If logging is not "Enabled", this is a finding.
Vulnerability Number
V-265488
Documentable
False
Rule Version
NT1F-4X-000004
Severity Override Guidance
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
For each Tier-1 Gateway and for each rule, click the gear icon and verify the logging setting.
If logging is not "Enabled", this is a finding.
Check Content Reference
M
Target Key
5632