NSX Catalogs
CloudControl supports operations that are grouped together in the NSX Operations Catalog Matrix. The matrix is located at Compliance > Templates > Edit Template NSX Operations Catalog Matrix.
Supported operations include:
-
Verify that NTP is authorized.
-
Enable remote syslog to configure remote logging for NSX Manager.
-
Ensure that the NSX Manager certificate is valid.
-
Enable in-protocol MDS authentication for OSPF and password for BGP.
-
Ensure IPv6 is disabled and not configured if it is not in use.
-
Disable SSH unless it is needed for diagnostics or troubleshooting.
-
Follow VMware Security Advisories and apply patches.
-
Secure the Controller network.
-
Prevents excluding audit logs and system events from backup.
-
Secure the backup directory.
-
Ensure that IPv4 DNS is authorized and secure the DNS server.
-
Ensure that the SFTP server on which backup is done is hardened.
-
Ensure that the syslog server is authorized and the configuration is appropriate.
-
Use SFTP for backup and restoration.
-
Use Load Balance - SRCID for the VXLAN vmknic teaming policy.