SV-233327r1113800_rule
V-233327
SRG-NET-000343-NAC-001470
FORE-NC-000190
CAT II
10
Use the Forescout Administrator UI to configure the policy which identifies nonentity endpoints to complete a control action when a device is added to the MAR.
1. Log on to Forescout UI.
2. In the Policy tab, locate the Authentication and Authorization policy set.
3. Select a policy that identifies nonentity endpoints. Highlight the policy, then select "Edit".
4. From the Sub-Rules section, ensure that when a device is added to the MAR, the policy also applies one of the following actions:
-Access Port ACL.
-Endpoint Address ACL.
-WLAN Role.
-VLAN Change.
If DOD is not at C2C Step 4 or higher, this is not a finding.
Verify Forescout applies dynamic ACLs (or VLAN restrictions) that restrict the use of ports when nonentity endpoints are connected using MAC Address Repository (MAR).
If the NAC does not apply dynamic ACLs (or VLAN restrictions) that restrict the use of ports when nonentity endpoints are connected using MAR, this is a finding.
V-233327
False
FORE-NC-000190
If DOD is not at C2C Step 4 or higher, this is not a finding.
Verify Forescout applies dynamic ACLs (or VLAN restrictions) that restrict the use of ports when nonentity endpoints are connected using MAC Address Repository (MAR).
If the NAC does not apply dynamic ACLs (or VLAN restrictions) that restrict the use of ports when nonentity endpoints are connected using MAR, this is a finding.
M
5250