STIGQter STIGQter: STIG Summary:

VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 30 Jan 2025

CheckedNameTitle
☐SV-265390r994520_ruleThe NSX Tier-0 Gateway router must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
☐SV-265393r994529_ruleThe NSX Tier-0 Gateway router must be configured to have all inactive interfaces removed.
☐SV-265404r999914_ruleThe NSX Tier-0 Gateway router must be configured to have the Dynamic Host Configuration Protocol (DHCP) service disabled if not in use.
☐SV-265406r994568_ruleThe NSX Tier-0 Gateway router must be configured to use encryption for Open Shortest Path First (OSPF) routing protocol authentication.
☐SV-265428r994634_ruleThe NSX Tier-0 Gateway router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field by enabling Unicast Reverse Path Forwarding (uRPF).
☐SV-265431r994643_ruleThe NSX Tier-0 Gateway router must be configured to implement message authentication for all control plane protocols.
☐SV-265432r994646_ruleThe NSX Tier-0 Gateway must be configured to use a unique password for each autonomous system (AS) with which it peers.
☐SV-265441r999915_ruleThe NSX Tier-0 Gateway router must be configured to have Internet Control Message Protocol (ICMP) unreachable notifications disabled on all external interfaces.
☐SV-265442r999916_ruleThe NSX Tier-0 Gateway router must be configured to have Internet Control Message Protocol (ICMP) mask replies disabled on all external interfaces.
☐SV-265443r999917_ruleThe NSX Tier-0 Gateway router must be configured to have Internet Control Message Protocol (ICMP) redirects disabled on all external interfaces.
☐SV-265444r994682_ruleThe NSX Tier-0 Gateway router must be configured to use the Border Gateway Protocol (BGP) maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.
☐SV-265468r994754_ruleThe NSX Tier-0 Gateway router must be configured to use its loopback address as the source address for Internal Border Gateway Protocol (IBGP) peering sessions.
☐SV-265479r994787_ruleThe NSX Tier-0 Gateway router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.
☐SV-265483r999918_ruleThe NSX Tier-0 Gateway router must be configured to have routing protocols disabled if not in use.
☐SV-265484r999919_ruleThe NSX Tier-0 Gateway router must be configured to have multicast disabled if not in use.
☐SV-265485r994805_ruleThe NSX Tier-0 Gateway router must be configured to use encryption for border gateway protocol (BGP) routing protocol authentication.