Skip to content

The NSX-T Manager must enable the global FIPS compliance mode for load balancers.

An XCCDF Rule

Description

If unsecured protocols (lacking cryptographic mechanisms) are used for load balancing, the contents of those sessions will be susceptible to eavesdropping, potentially putting sensitive data at risk of compromise.

ID
SV-251800r879588_rule
Version
TNDM-3X-000103
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Execute the following API call using curl or another REST API client:

PUT https://<nsx-mgr>/policy/api/v1/infra/global-config

Example request body: