STIGQter STIGQter: STIG Summary: SDN Using NV Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 Feb 2017:

The proper multicast group for each Virtual Extensible Local Area Network (VXLAN) identifier must be mapped to the appropriate virtual tunnel endpoint (VTEP) so the VTEP will join the associated multicast groups.

DISA Rule

SV-87763r1_rule

Vulnerability Number

V-73111

Group Title

NET-SDN-022

Rule Version

NET-SDN-022

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the appropriate multicast group that is assigned to each VNI on all VXLAN-enabled switches.

Check Contents

Review the VXLAN topology as well as documentation for the SDN deployment that identifies each VXLAN segment via VNI and the associated multicast groups.

Review the VTEP configuration of all physical VXLAN-enabled switches to verify that the appropriate multicast group is defined for each VNI.

If the appropriate multicast group is not configured for each member VNI, this is a finding.

Note: This requirement is only applicable to VNIs that must be defined on each VXLAN-enabled switch. In addition, this requirement is applicable to the implementation of technologies similar to VXLAN (e.g., NVGRE, STT) for the purpose of transporting traffic between virtual machines residing on different physical hosts.

Vulnerability Number

V-73111

Documentable

False

Rule Version

NET-SDN-022

Severity Override Guidance

Review the VXLAN topology as well as documentation for the SDN deployment that identifies each VXLAN segment via VNI and the associated multicast groups.

Review the VTEP configuration of all physical VXLAN-enabled switches to verify that the appropriate multicast group is defined for each VNI.

If the appropriate multicast group is not configured for each member VNI, this is a finding.

Note: This requirement is only applicable to VNIs that must be defined on each VXLAN-enabled switch. In addition, this requirement is applicable to the implementation of technologies similar to VXLAN (e.g., NVGRE, STT) for the purpose of transporting traffic between virtual machines residing on different physical hosts.

Check Content Reference

M

Target Key

3089

Comments