STIGQter STIGQter: STIG Summary: Solaris 10 SPARC Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

The system's local firewall must implement a deny-all, allow-by-exception policy.

DISA Rule

SV-227072r603265_rule

Vulnerability Number

V-227072

Group Title

SRG-OS-000297

Rule Version

GEN008540

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit /etc/ipf/ipf.conf and add a default deny rule.
Restart the ipfilter service.
# svcadm restart network/ipfilter

Check Contents

If the system is not a global zone, this vulnerability is not applicable.

Check the firewall rules for a default deny rule.
# ipfstat -i

An example of a default deny rule is:
block in log quick on ne3 from any to any.

If there is no default deny rule, this is a finding.

Vulnerability Number

V-227072

Documentable

False

Rule Version

GEN008540

Severity Override Guidance

If the system is not a global zone, this vulnerability is not applicable.

Check the firewall rules for a default deny rule.
# ipfstat -i

An example of a default deny rule is:
block in log quick on ne3 from any to any.

If there is no default deny rule, this is a finding.

Check Content Reference

M

Target Key

4060

Comments