STIGQter STIGQter: STIG Summary: Network WLAN AP-NIPR Management Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 25 Oct 2023:

The network device must be configured with both an ingress and egress ACL.

DISA Rule

SV-243169r879887_rule

Vulnerability Number

V-243169

Group Title

SRG-APP-000516-NDM-000335

Rule Version

WLAN-ND-001800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the management interface is a routed interface, configure it with both an ingress and egress ACL. The ingress ACL should block any transit traffic, while the egress ACL should block any traffic that was not originated by the managed network device.

Check Contents

1. Verify the managed interface has an inbound and outbound ACL or filter.

2. Verify the ingress ACL blocks all transit traffic (any traffic not destined to the router itself). In addition, traffic accessing the managed elements should be originated at the NOC.

3. Verify the egress ACL blocks any traffic not originated by the managed element.

If the management interface does not have an ingress and egress filter configured and applied, this is a finding.

Vulnerability Number

V-243169

Documentable

False

Rule Version

WLAN-ND-001800

Severity Override Guidance

1. Verify the managed interface has an inbound and outbound ACL or filter.

2. Verify the ingress ACL blocks all transit traffic (any traffic not destined to the router itself). In addition, traffic accessing the managed elements should be originated at the NOC.

3. Verify the egress ACL blocks any traffic not originated by the managed element.

If the management interface does not have an ingress and egress filter configured and applied, this is a finding.

Check Content Reference

M

Target Key

5392