STIGQter STIGQter: STIG Summary:

VMware NSX-T Tier 1 Gateway Firewall Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 26 Jul 2023

CheckedNameTitle
SV-251761r810178_ruleThe NSX-T Tier-1 Gateway Firewall must generate traffic log entries containing information to establish what type of events occurred.
SV-251762r919235_ruleThe NSX-T Tier-1 Gateway Firewall must generate traffic log entries containing information to establish the details of the event.
SV-251763r919237_ruleEach NSX-T Edge Node configured to host a Tier-1 Gateway Firewall must be configured to use the TLS or LI-TLS protocols to configure and secure traffic log records.
SV-251764r919240_ruleThe NSX-T Tier-1 Gateway Firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints.
SV-251765r810190_ruleThe NSX-T Tier-1 Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
SV-251766r863248_ruleThe NSX-T Tier-1 Gateway Firewall must be configured to send traffic log entries to a central audit server for management and configuration of the traffic log entries.
SV-251767r856686_ruleThe NSX-T Tier-1 Gateway Firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning.
SV-251768r856687_ruleThe NSX-T Tier-1 Gateway Firewall must apply ingress filters to traffic that is inbound to the network through any active external interface.
SV-251769r856688_ruleThe NSX-T Tier-1 Gateway Firewall must configure SpoofGuard to block outbound IP packets that contain illegitimate packet attributes.