STIGQter STIGQter: STIG Summary:

VMware NSX 4.x Tier-0 Gateway Router Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 30 Jan 2025

CheckedNameTitle
SV-265390r994520_ruleThe NSX Tier-0 Gateway router must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.
SV-265393r994529_ruleThe NSX Tier-0 Gateway router must be configured to have all inactive interfaces removed.
SV-265404r999914_ruleThe NSX Tier-0 Gateway router must be configured to have the Dynamic Host Configuration Protocol (DHCP) service disabled if not in use.
SV-265406r994568_ruleThe NSX Tier-0 Gateway router must be configured to use encryption for Open Shortest Path First (OSPF) routing protocol authentication.
SV-265428r994634_ruleThe NSX Tier-0 Gateway router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field by enabling Unicast Reverse Path Forwarding (uRPF).
SV-265431r994643_ruleThe NSX Tier-0 Gateway router must be configured to implement message authentication for all control plane protocols.
SV-265432r994646_ruleThe NSX Tier-0 Gateway must be configured to use a unique password for each autonomous system (AS) with which it peers.
SV-265441r999915_ruleThe NSX Tier-0 Gateway router must be configured to have Internet Control Message Protocol (ICMP) unreachable notifications disabled on all external interfaces.
SV-265442r999916_ruleThe NSX Tier-0 Gateway router must be configured to have Internet Control Message Protocol (ICMP) mask replies disabled on all external interfaces.
SV-265443r999917_ruleThe NSX Tier-0 Gateway router must be configured to have Internet Control Message Protocol (ICMP) redirects disabled on all external interfaces.
SV-265444r994682_ruleThe NSX Tier-0 Gateway router must be configured to use the Border Gateway Protocol (BGP) maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.
SV-265468r994754_ruleThe NSX Tier-0 Gateway router must be configured to use its loopback address as the source address for Internal Border Gateway Protocol (IBGP) peering sessions.
SV-265479r994787_ruleThe NSX Tier-0 Gateway router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.
SV-265483r999918_ruleThe NSX Tier-0 Gateway router must be configured to have routing protocols disabled if not in use.
SV-265484r999919_ruleThe NSX Tier-0 Gateway router must be configured to have multicast disabled if not in use.
SV-265485r994805_ruleThe NSX Tier-0 Gateway router must be configured to use encryption for border gateway protocol (BGP) routing protocol authentication.