SV-265612r993933_rule
V-265612
SRG-NET-000074-FW-000009
NDFW-4X-000004
CAT III
10
From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules.
For each rule that has logging disabled, click the gear icon, toggle the logging option to "Enable", and click "Apply".
or
For each Policy or Section, click the menu icon on the left and select "Enable Logging for All Rules".
After all changes are made, click "Publish".
NOTE: Syslog and alert monitoring procedure: Syslog configuration is in the vSphere ESXi STIG where there is a control to require syslog configuration. This is because the NSX Distributed Firewall data plane is not directly configured to communicate with the central log server/syslog. The firewall runs in a distributed manner across ESXi hosts, and the traffic logs for the DFW are located on each host for the traffic it processes and are forwarded from each host to a centralized syslog server. Thus, ESXi hosts must be configured to send the syslogs to the log server. In turn, the syslog must be configured to send all required alerts, including when unknown or out-of-order extension headers are detected in inbound and outbound IPv6 traffic.
From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> All Rules.
For each rule, click the gear icon and verify the logging setting.
If logging is not enabled for any rule, this is a finding.
V-265612
False
NDFW-4X-000004
From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> All Rules.
For each rule, click the gear icon and verify the logging setting.
If logging is not enabled for any rule, this is a finding.
M
5630