STIGQter STIGQter: STIG Summary: Firewall Security Requirements Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The firewall must restrict traffic entering the VPN tunnels to the management network to only the authorized management packets based on destination address.

DISA Rule

SV-206708r604133_rule

Vulnerability Number

V-206708

Group Title

SRG-NET-000364

Rule Version

SRG-NET-000364-FW-000036

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Where IPsec technology is deployed to connect the managed network to the NOC, restrict the traffic entering the tunnels so that only the authorized management packets with authorized destination addresses are permitted.

Check Contents

Inspect the architecture diagrams. Inspect the NOC and the managed network. Note that the IPsec tunnel endpoints may be configured on the premise or gateway router, the VPN gateway firewall, or a VPN concentrator.

Verify that all traffic between the managed network and management network and vice-versa is secured via IPsec encapsulation.

If the firewall does not restrict traffic entering the VPN tunnels to the management network to only the authorized management packets based on destination address, this is a finding.

Vulnerability Number

V-206708

Documentable

False

Rule Version

SRG-NET-000364-FW-000036

Severity Override Guidance

Inspect the architecture diagrams. Inspect the NOC and the managed network. Note that the IPsec tunnel endpoints may be configured on the premise or gateway router, the VPN gateway firewall, or a VPN concentrator.

Verify that all traffic between the managed network and management network and vice-versa is secured via IPsec encapsulation.

If the firewall does not restrict traffic entering the VPN tunnels to the management network to only the authorized management packets based on destination address, this is a finding.

Check Content Reference

M

Target Key

2912

Comments