STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-1 Gateway Firewall Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-1 Gateway firewall must be configured to inspect traffic at the application layer.

DISA Rule

SV-265500r994869_rule

Vulnerability Number

V-265500

Group Title

SRG-NET-000364-FW-000040

Rule Version

NT1F-4X-000027

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway and each rule that should have a Context Profile enabled, click the pencil icon in the Context Profile column.

Select an existing Context Profile or create a custom one then click "Apply".

After all changes are made, click "Publish".

Not all App IDs will be suitable for use in all cases and should be evaluated in each environment before use.

A list of App IDs for application layer rules is available here: https://docs.vmware.com/en/NSX-Application-IDs/index.html.

Check Contents

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway, review rules that do not have a Context Profile assigned.

For example, if a rule exists to allow SSH by service or custom port then it should have the associated SSH Context Profile applied.

If any rules with services defined have an associated suitable Context Profile but do not have one applied, this is a finding.

Vulnerability Number

V-265500

Documentable

False

Rule Version

NT1F-4X-000027

Severity Override Guidance

From the NSX Manager web interface, go to Security >> Policy Management >> Gateway Firewall >> Gateway Specific Rules.

For each Tier-1 Gateway, review rules that do not have a Context Profile assigned.

For example, if a rule exists to allow SSH by service or custom port then it should have the associated SSH Context Profile applied.

If any rules with services defined have an associated suitable Context Profile but do not have one applied, this is a finding.

Check Content Reference

M

Target Key

5632