STIGQter STIGQter: STIG Summary: VMware NSX 4.x Distributed Firewall Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Distributed Firewall must generate traffic log entries that can be sent by the ESXi hosts to the central syslog.

DISA Rule

SV-265612r993933_rule

Vulnerability Number

V-265612

Group Title

SRG-NET-000074-FW-000009

Rule Version

NDFW-4X-000004

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules.

For each rule that has logging disabled, click the gear icon, toggle the logging option to "Enable", and click "Apply".

or

For each Policy or Section, click the menu icon on the left and select "Enable Logging for All Rules".

After all changes are made, click "Publish".

NOTE: Syslog and alert monitoring procedure: Syslog configuration is in the vSphere ESXi STIG where there is a control to require syslog configuration. This is because the NSX Distributed Firewall data plane is not directly configured to communicate with the central log server/syslog. The firewall runs in a distributed manner across ESXi hosts, and the traffic logs for the DFW are located on each host for the traffic it processes and are forwarded from each host to a centralized syslog server. Thus, ESXi hosts must be configured to send the syslogs to the log server. In turn, the syslog must be configured to send all required alerts, including when unknown or out-of-order extension headers are detected in inbound and outbound IPv6 traffic.

Check Contents

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> All Rules.

For each rule, click the gear icon and verify the logging setting.

If logging is not enabled for any rule, this is a finding.

Vulnerability Number

V-265612

Documentable

False

Rule Version

NDFW-4X-000004

Severity Override Guidance

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> All Rules.

For each rule, click the gear icon and verify the logging setting.

If logging is not enabled for any rule, this is a finding.

Check Content Reference

M

Target Key

5630