STIGQter STIGQter: STIG Summary: Nutanix Acropolis GPOS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix AHV must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring the operating system is implementing rate-limiting measures on impacted network interfaces.

DISA Rule

SV-279685r1192527_rule

Vulnerability Number

V-279685

Group Title

SRG-OS-000420-GPOS-00186

Rule Version

NXAC-OS-000272

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Nutanix AHV firewall services using the following command.

$ sudo salt-call state.sls security/KVM/iptablesKVM

Check Contents

For AOS, Prism Central, and Files, this requirement is Not Applicable.

Verify "firewalld" has "nftables" set as the default backend using the following command.

$ sudo grep -i firewallbackend /etc/firewalld/firewalld.conf

# FirewallBackend
FirewallBackend=nftables

If the "nftables" is not set as the "firewallbackend" default, this is a finding.

Vulnerability Number

V-279685

Documentable

False

Rule Version

NXAC-OS-000272

Severity Override Guidance

For AOS, Prism Central, and Files, this requirement is Not Applicable.

Verify "firewalld" has "nftables" set as the default backend using the following command.

$ sudo grep -i firewallbackend /etc/firewalld/firewalld.conf

# FirewallBackend
FirewallBackend=nftables

If the "nftables" is not set as the "firewallbackend" default, this is a finding.

Check Content Reference

M

Target Key

5730