VMware NSX-T SDN Controller Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 5 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001665
- Version
- TSDC-3X-000011
- Vuln IDs
-
- V-251734
- Rule IDs
-
- SV-251734r810060_rule
Checks: C-55171r810058_chk
From the NSX-T Manager web interface, go to System >> Appliances. Verify there are three NSX-T Managers deployed, a VIP or external load balancer is configured, and the cluster is in a healthy state. If there are not three NSX-T Managers deployed and a VIP or external load balancer configured and the cluster is in a healthy state, this is a finding.
Fix: F-55125r810059_fix
To add additional NSX-T Manager appliances do the following: From the NSX-T Manager web interface, go to System >>Appliances, and then click "Add NSX Appliance". Supply the required information to add additional nodes as needed, up to three total. To configure NSX-T with a cluster VIP or external load balancer do the following: From the NSX-T Manager web interface, go to System >> Appliances, and then click "Set Virtual IP", enter a VIP that is part of the same subnet as the other management nodes, and then click "Save". To configure NSX-T with an external load balancer, setup an external load balancer with the following requirements: - Configure the external load balancer to control traffic to the NSX Manager nodes. - Configure the external load balancer to use the round robin method and configure source persistence for the load balancer's virtual IP. - Create or import a signed certificate and apply the same certificate to all the NSX Manager nodes. The certificate must have the FQDN of the virtual IP and each of the nodes in the SAN. Note: An external load balancer will not work with the NSX Manager VIP. Do not configure an NSX Manager VIP if using an external load balancer. If the cluster status is not in a healthy state identify the degraded component on the appliance and troubleshoot the issue with the error information provided.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- TSDC-3X-000020
- Vuln IDs
-
- V-251735
- Rule IDs
-
- SV-251735r810063_rule
Checks: C-55172r810061_chk
This check must be performed in vCenter. From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX-T Managers are deployed >> Configure >> Configuration >> VM/Host Rules. If the NSX-T Manager cluster does not have rules applied to it that separate the nodes onto different physical hosts, this is a finding.
Fix: F-55126r810062_fix
This fix must be performed in vCenter. From the vSphere Client, go to Administration >> Hosts and Clusters >> Select the cluster where the NSX-T Managers are deployed >> Configure >> Configuration >> VM/Host Rules. Click "Add" to create a new rule. Provide a name and select "Separate Virtual Machines" under Type. Add the three NSX-T Manager virtual machines to the list and click "OK".