STIGQter STIGQter: STIG Summary:

VMware NSX-T Tier-0 Gateway RTR Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 02 Sep 2022

CheckedNameTitle
SV-251744r810116_ruleThe NSX-T Tier-0 Gateway must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).
SV-251745r810119_ruleThe NSX-T Tier-0 Gateway must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
SV-251746r810122_ruleThe NSX-T Tier-0 Gateway must be configured to have all inactive interfaces removed.
SV-251747r810125_ruleThe NSX-T Tier-0 Gateway must be configured to have the DHCP service disabled if not in use.
SV-251748r810128_ruleThe NSX-T Tier-0 Gateway must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.
SV-251749r810131_ruleThe NSX-T Tier-0 Gateway must be configured to restrict traffic destined to itself.
SV-251750r810134_ruleUnicast Reverse Path Forwarding (uRPF) must be enabled on the NSX-T Tier-0 Gateway.
SV-251751r856692_ruleThe NSX-T Tier-0 Gateway must be configured to implement message authentication for all control plane protocols.
SV-251752r856693_ruleThe NSX-T Tier-0 Gateway must be configured to use a unique key for each autonomous system (AS) with which it peers.
SV-251753r856694_ruleThe NSX-T Tier-0 Gateway must be configured to have Internet Control Message Protocol (ICMP) unreachable notifications disabled on all external interfaces.
SV-251754r856695_ruleThe NSX-T Tier-0 Gateway must be configured to have Internet Control Message Protocol (ICMP) mask replies disabled on all external interfaces.
SV-251755r856696_ruleThe NSX-T Tier-0 Gateway must be configured to have Internet Control Message Protocol (ICMP) redirects disabled on all external interfaces.
SV-251756r856697_ruleThe NSX-T Tier-0 Gateway must be configured to use the BGP maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.
SV-251757r810155_ruleThe NSX-T Tier-0 Gateway must be configured to use its loopback address as the source address for iBGP peering sessions.
SV-251758r810158_ruleThe NSX-T Tier-0 Gateway must be configured to have routing protocols disabled if not in use.
SV-251759r810161_ruleThe NSX-T Tier-0 Gateway must be configured to have multicast disabled if not in use.