SV-265500r994869_rule
V-265500
SRG-NET-000364-FW-000040
NT1F-4X-000027
CAT II
10
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
For each Tier-1 Gateway and each rule that should have a Context Profile enabled, click the pencil icon in the Context Profile column.
Select an existing Context Profile or create a custom one then click "Apply".
After all changes are made, click "Publish".
Not all App IDs will be suitable for use in all cases and should be evaluated in each environment before use.
A list of App IDs for application layer rules is available here: https://docs.vmware.com/en/NSX-Application-IDs/index.html.
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
For each Tier-1 Gateway, review rules that do not have a Context Profile assigned.
For example, if a rule exists to allow SSH by service or custom port then it should have the associated SSH Context Profile applied.
If any rules with services defined have an associated suitable Context Profile but do not have one applied, this is a finding.
V-265500
False
NT1F-4X-000027
From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.
For each Tier-1 Gateway, review rules that do not have a Context Profile assigned.
For example, if a rule exists to allow SSH by service or custom port then it should have the associated SSH Context Profile applied.
If any rules with services defined have an associated suitable Context Profile but do not have one applied, this is a finding.
M
5632