| Checked | Name | Title |
|---|
| ☐ | SV-251737r810078_rule | The NSX-T Tier-0 Gateway Firewall must generate traffic log entries containing information to establish the details of the event. |
| ☐ | SV-251738r919225_rule | The NSX-T Tier-0 Gateway Firewall must be configured to use the TLS or LI-TLS protocols to configure and secure communications with the central audit server. |
| ☐ | SV-251739r919228_rule | The NSX-T Tier-0 Gateway Firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints. |
| ☐ | SV-251740r810087_rule | The NSX-T Tier-1 Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). |
| ☐ | SV-251741r856690_rule | The NSX-T Tier-0 Gateway Firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning. |
| ☐ | SV-251742r856691_rule | The NSX-T Tier-0 Gateway Firewall must apply ingress filters to traffic that is inbound to the network through any active external interface. |
| ☐ | SV-251743r810096_rule | The NSX-T Tier-0 Gateway Firewall must configure SpoofGuard to block outbound IP packets that contain illegitimate packet attributes. |