STIGQter STIGQter: STIG Summary: VMware NSX 4.x Distributed Firewall Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Distributed Firewall must deny network communications traffic by default and allow network communications traffic by exception.

DISA Rule

SV-265619r993954_rule

Vulnerability Number

V-265619

Group Title

SRG-NET-000202-FW-000039

Rule Version

NDFW-4X-000016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule and change action to "Drop" or "Reject".

After all changes are made, click "Publish".

Note: Before enabling, ensure the necessary rules to whitelist approved traffic are created and published, or this change may result in loss of communication for workloads.

Check Contents

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.

If the Default Layer3 Rule is set to "ALLOW", this is a finding.

Vulnerability Number

V-265619

Documentable

False

Rule Version

NDFW-4X-000016

Severity Override Guidance

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.

If the Default Layer3 Rule is set to "ALLOW", this is a finding.

Check Content Reference

M

Target Key

5630