STIGQter STIGQter: STIG Summary: VMware NSX 4.x Distributed Firewall Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Distributed Firewall must be configured to inspect traffic at the application layer.

DISA Rule

SV-265628r993981_rule

Vulnerability Number

V-265628

Group Title

SRG-NET-000364-FW-000040

Rule Version

NDFW-4X-000027

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, navigate to Security >> Policy Management >> Distributed Firewall >> Category Specific Rules.

For each rule that should have a Context Profile enabled, click the pencil icon in the Context Profile column.

Select an existing Context Profile or create a custom one then click "Apply".

After all changes are made, click "Publish".

Note: This control does not apply to Ethernet rules.

Not all App IDs will be suitable for use in all cases and should be evaluated in each environment before use.

A list of App IDs for application layer rules is available here: https://docs.vmware.com/en/NSX-Application-IDs/index.html.

Check Contents

From the NSX Manager web interface, navigate to Security >> Distributed Firewall >> All Rules.

Review rules that do not have a Context Profile assigned. For example, if a rule exists to allow SSH by service or custom port, then it should have the associated SSH Context Profile applied.

If any rules with services defined have an associated suitable Context Profile but do not have one applied, this is a finding.

Vulnerability Number

V-265628

Documentable

False

Rule Version

NDFW-4X-000027

Severity Override Guidance

From the NSX Manager web interface, navigate to Security >> Distributed Firewall >> All Rules.

Review rules that do not have a Context Profile assigned. For example, if a rule exists to allow SSH by service or custom port, then it should have the associated SSH Context Profile applied.

If any rules with services defined have an associated suitable Context Profile but do not have one applied, this is a finding.

Check Content Reference

M

Target Key

5630