SV-265619r993954_rule
V-265619
SRG-NET-000202-FW-000039
NDFW-4X-000016
CAT II
10
From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule and change action to "Drop" or "Reject".
After all changes are made, click "Publish".
Note: Before enabling, ensure the necessary rules to whitelist approved traffic are created and published, or this change may result in loss of communication for workloads.
From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.
If the Default Layer3 Rule is set to "ALLOW", this is a finding.
V-265619
False
NDFW-4X-000016
From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules >> APPLICATION >> Default Layer3 Section >> Default Layer3 Rule >> Action.
If the Default Layer3 Rule is set to "ALLOW", this is a finding.
M
5630