STIGQter STIGQter: STIG Summary: Solaris 10 X86 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

The system must employ a local firewall.

DISA Rule

SV-227980r603266_rule

Vulnerability Number

V-227980

Group Title

SRG-OS-000480

Rule Version

GEN008520

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable the system's local firewall.
# svcadm enable network/ipfilter

Check Contents

Determine the zone that you are currently securing.

# zonename

If the command output is "global", only the "phys" and "SR-IOV" interfaces assigned to the global zone require inspection. If using a non-Global zone, all "phys" and "SR-IOV" interfaces assigned to the zone require inspection.

Determine if the system is using a local firewall.
# svcs network/ipfilter
If the service is not online, this is a finding.

Vulnerability Number

V-227980

Documentable

False

Rule Version

GEN008520

Severity Override Guidance

Determine the zone that you are currently securing.

# zonename

If the command output is "global", only the "phys" and "SR-IOV" interfaces assigned to the global zone require inspection. If using a non-Global zone, all "phys" and "SR-IOV" interfaces assigned to the zone require inspection.

Determine if the system is using a local firewall.
# svcs network/ipfilter
If the service is not online, this is a finding.

Check Content Reference

M

Target Key

4061

Comments