| Checked | Name | Title |
|---|
| ☐ | SV-251727r810035_rule | The NSX-T Distributed Firewall must generate traffic log entries containing information to establish the details of the event. |
| ☐ | SV-251728r919499_rule | The NSX-T Distributed Firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints. |
| ☐ | SV-251729r810041_rule | The NSX-T Distributed Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). |
| ☐ | SV-251730r863248_rule | The NSX-T Distributed Firewall must be configured to send traffic log entries to a central audit server for management and configuration of the traffic log entries. |
| ☐ | SV-251731r856683_rule | The NSX-T Distributed Firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning. |
| ☐ | SV-251732r856684_rule | The NSX-T Distributed Firewall must configure SpoofGuard to block outbound IP packets that contain illegitimate packet attributes. |
| ☐ | SV-251733r810053_rule | The NSX-T Distributed Firewall must verify time-based firewall rules. |