SV-239852r665842_rule
V-239852
SRG-NET-000019-FW-000003
CASA-FW-000010
CAT I
10
Step 1: Configure the ingress ACL similar to the example below.
ASA(config)# access-list INSIDE_INextended permit tcp any any eq https
ASA(config)# access-list INSIDE_INextended permit tcp any any eq http
ASA(config)# access-list INSIDE_INextended permit tcp any any eq …
ASA(config)# access-list INSIDE_INextended deny ip any any log
Step 2: Apply the ACL inbound on all internal interfaces as shown in the example below.
ASA(config)# access-group INSIDE_IN in interface INSIDE
ASA(config)# end
Review the ASA configuration to determine if it only permits outbound traffic using authorized ports and services.
Step 1: Verify that an ingress ACL has been applied to all internal interfaces as shown in the example below.
interface GigabitEthernet0/0
nameif INSIDE
security-level 100
ip address 10.1.11.1 255.255.255.0
…
…
…
access-group INSIDE _IN in interface INSIDE
Step 2: Verify that the ingress ACL only allows outbound traffic using authorized ports and services as shown in the example below.
access-list INSIDE _IN extended permit tcp any any eq www
access-list INSIDE _IN extended permit tcp any any eq https
access-list INSIDE _IN extended permit tcp any any eq …
access-list INSIDE _IN extended deny ip any any log
If the ASA is not configured to only allow outbound traffic using authorized ports and services, this is a finding.
V-239852
False
CASA-FW-000010
Review the ASA configuration to determine if it only permits outbound traffic using authorized ports and services.
Step 1: Verify that an ingress ACL has been applied to all internal interfaces as shown in the example below.
interface GigabitEthernet0/0
nameif INSIDE
security-level 100
ip address 10.1.11.1 255.255.255.0
…
…
…
access-group INSIDE _IN in interface INSIDE
Step 2: Verify that the ingress ACL only allows outbound traffic using authorized ports and services as shown in the example below.
access-list INSIDE _IN extended permit tcp any any eq www
access-list INSIDE _IN extended permit tcp any any eq https
access-list INSIDE _IN extended permit tcp any any eq …
access-list INSIDE _IN extended deny ip any any log
If the ASA is not configured to only allow outbound traffic using authorized ports and services, this is a finding.
M
5339