STIGQter STIGQter: STIG Summary:

VMware NSX 4.x Manager NDM Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 30 Jan 2025

CheckedNameTitle
SV-265289r994090_ruleThe NSX Manager must configure logging levels for services to ensure audit records are generated.
SV-265292r994099_ruleThe NSX Manager must assign users/accounts to organization-defined roles configured with approved authorizations.
SV-265293r994102_ruleThe NSX Manager must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-265294r994105_ruleThe NSX Manager must display the Standard Mandatory DOD Notice and Consent Banner before granting access.
SV-265295r994108_ruleThe NSX Manager must retain the Standard Mandatory DOD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log on for further access.
SV-265296r994111_ruleThe NSX Manager must be configured to integrate with an identity provider that supports multifactor authentication (MFA).
SV-265313r1051115_ruleThe NSX Manager must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-265315r994168_ruleThe NSX Manager must only enable TLS 1.2 or greater.
SV-265316r994171_ruleThe NSX Manager must enforce a minimum 15-character password length for local accounts.
SV-265317r994174_ruleThe NSX Manager must enforce password complexity by requiring that at least one uppercase character be used for local accounts.
SV-265318r994177_ruleThe NSX Manager must enforce password complexity by requiring that at least one lowercase character be used for local accounts.
SV-265319r994180_ruleThe NSX Manager must enforce password complexity by requiring that at least one numeric character be used for local accounts.
SV-265320r994183_ruleThe NSX Manager must enforce password complexity by requiring that at least one special character be used for local accounts.
SV-265321r1043189_ruleThe NSX Manager must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
SV-265327r994204_ruleThe NSX Manager must terminate all network connections associated with a session after five minutes of inactivity.
SV-265338r994237_ruleThe NSX Manager must be configured to synchronize internal information system clocks using redundant authoritative time sources.
SV-265339r994240_ruleThe NSX Manager must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC).
SV-265346r994261_ruleThe NSX Manager must be configured to protect against denial-of-service (DoS) attacks by limit the number of concurrent sessions to an organization-defined number.
SV-265348r994267_ruleThe NSX Manager must be configured to send logs to a central log server.
SV-265349r994270_ruleThe NSX Manager must not provide environment information to third parties.
SV-265350r994273_ruleThe NSX Manager must be configured to conduct backups on an organizationally defined schedule.
SV-265351r994276_ruleThe NSX Manager must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-265352r994279_ruleThe NSX Manager must be running a release that is currently supported by the vendor.
SV-265353r994282_ruleThe NSX Manager must disable SSH.
SV-265354r994285_ruleThe NSX Manager must disable SNMP v2.
SV-265355r994288_ruleThe NSX Manager must enable the global FIPS compliance mode for load balancers.
SV-265358r994297_ruleThe NSX Manager must be configured as a cluster.
SV-265359r994300_ruleThe NSX Managers must be deployed on separate physical hosts.