STIGQter STIGQter: STIG Summary: VMware NSX 4.x Tier-1 Gateway Router Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Tier-1 Gateway router must be configured to have multicast disabled if not in use.

DISA Rule

SV-265608r999927_rule

Vulnerability Number

V-265608

Group Title

SRG-NET-000131-RTR-000035

Rule Version

NT1R-4X-000107

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

If not used, disable Multicast by doing the following:

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-1 Gateways and edit the target Tier-1 gateway.

Expand Multicast and change from "Enabled" to "Disabled" and then click "Save".

Check Contents

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-1 Gateways.

For every Tier-1 Gateway, expand the Tier-1 Gateway then expand Multicast to view the Multicast configuration.

If Multicast is enabled and not in use, this is a finding.

If a Tier-1 Gateway is not linked to a Tier-0 Gateway, this is Not Applicable.

Vulnerability Number

V-265608

Documentable

False

Rule Version

NT1R-4X-000107

Severity Override Guidance

From the NSX Manager web interface, go to Networking >> Connectivity >> Tier-1 Gateways.

For every Tier-1 Gateway, expand the Tier-1 Gateway then expand Multicast to view the Multicast configuration.

If Multicast is enabled and not in use, this is a finding.

If a Tier-1 Gateway is not linked to a Tier-0 Gateway, this is Not Applicable.

Check Content Reference

M

Target Key

5635