STIGQter STIGQter: STIG Summary:

VMware NSX 4.x Distributed Firewall Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 30 Jan 2025

CheckedNameTitle
SV-265612r993933_ruleThe NSX Distributed Firewall must generate traffic log entries that can be sent by the ESXi hosts to the central syslog.
SV-265618r993951_ruleThe NSX Distributed Firewall must limit the effects of packet flooding types of denial-of-service (DoS) attacks.
SV-265619r993954_ruleThe NSX Distributed Firewall must deny network communications traffic by default and allow network communications traffic by exception.
SV-265628r993981_ruleThe NSX Distributed Firewall must be configured to inspect traffic at the application layer.
SV-265630r993987_ruleThe NSX Distributed Firewall must configure SpoofGuard to restrict it from accepting outbound packets that contain an illegitimate address in the source address.
SV-265633r993996_ruleThe NSX Distributed Firewall must configure an IP Discovery profile to disable trust on every use method.