The NSX-T Manager must enable the global FIPS compliance mode for load balancers.
An XCCDF Rule
Description
If unsecured protocols (lacking cryptographic mechanisms) are used for load balancing, the contents of those sessions will be susceptible to eavesdropping, potentially putting sensitive data at risk of compromise.
- ID
- SV-251800r879588_rule
- Version
- TNDM-3X-000103
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Execute the following API call using curl or another REST API client:
PUT https://<nsx-mgr>/policy/api/v1/infra/global-config
Example request body: