STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 28 Oct 2025:

The IPS must block malicious Internet Control Message Protocol (ICMP) packets by properly configuring ICMP signatures and rules.

DISA Rule

SV-206894r1137743_rule

Vulnerability Number

V-206894

Group Title

SRG-NET-000273

Rule Version

SRG-NET-000273-IDPS-00204

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IPS to block malicious ICMP packets by properly configuring ICMP signatures and rules.

Check Contents

If the device being reviewed is an IDS, this is not applicable.

Verify the IPS blocks malicious ICMP packets by properly configuring ICMP signatures and rules.

If the IPS does not block malicious ICMP packets by properly configuring ICMP signatures and rules, this is a finding.

Vulnerability Number

V-206894

Documentable

False

Rule Version

SRG-NET-000273-IDPS-00204

Severity Override Guidance

If the device being reviewed is an IDS, this is not applicable.

Verify the IPS blocks malicious ICMP packets by properly configuring ICMP signatures and rules.

If the IPS does not block malicious ICMP packets by properly configuring ICMP signatures and rules, this is a finding.

Check Content Reference

M

Target Key

2918