STIGQter STIGQter: STIG Summary: WLAN Access Point (Internet Gateway Only Connection) Security Technical Implementation Guide (STIG) Version: 6 Release: 14 Benchmark Date: 27 Apr 2018:

DoD Components providing guest WLAN access (Internet access only) must use separate WLAN or logical segmentation of the enterprise WLAN (e.g., separate service set identifier (SSID) and virtual LAN) or DoD network.

DISA Rule

SV-102343r1_rule

Vulnerability Number

V-92241

Group Title

Guest WLAN infrastructure placement

Rule Version

WIR0123-1

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Reconfigure physical and logical connections as needed so the Internet-only guest WLAN infrastructure resides in a dedicated subnet off the perimeter firewall or installed as a completely separate Internet-connection only WLAN system with no access to the enterprise network.

Check Contents

Have the SA show how the guest WLAN is physically connected to the firewall or supporting switch and how it is logically connected through firewall or switch configuration settings.

Verify the equipment is connected via a separate WLAN or logical segmentation of the host WLAN (e.g., separate service set identifier (SSID) and virtual LAN).

Verify the guest WLAN only provides Internet access.

If a guest WLAN is not set up as a separate WLAN from the DoD network or not set up as a logical segmentation from the DoD network or DoD WLAN, this is a finding.

If the guest WLAN does not only provide Internet access, this is a finding.

Vulnerability Number

V-92241

Documentable

False

Rule Version

WIR0123-1

Severity Override Guidance

Have the SA show how the guest WLAN is physically connected to the firewall or supporting switch and how it is logically connected through firewall or switch configuration settings.

Verify the equipment is connected via a separate WLAN or logical segmentation of the host WLAN (e.g., separate service set identifier (SSID) and virtual LAN).

Verify the guest WLAN only provides Internet access.

If a guest WLAN is not set up as a separate WLAN from the DoD network or not set up as a logical segmentation from the DoD network or DoD WLAN, this is a finding.

If the guest WLAN does not only provide Internet access, this is a finding.

Check Content Reference

M

Target Key

545

Comments