SV-250985r1028212_rule
V-250985
SRG-APP-000038-NDM-000213
MOIS-ND-000130
CAT III
10
Configure Sentry to enforce approved authorizations for controlling the flow of management information within the network device.
Sentry receives a request from MobileIron Core and enforces verification before handling the request to validate that it is from a trusted MobileIron Core.
Therefore, if the deployment uses MobileIron Core, to ensure that Sentry trusts MobileIron Core in the deployment, run the following commands in Sentry CLI:
1. sentry emm-source-verify true
2. sentry emm-ips <subnet_list>>
3. This can further be mitigated by creating ACLs for Sentry System Manager.
Then:
1. In the Standalone Sentry System Manager, go to Security >> Access Control Lists.
2. Click "Add".
3. In the "Name" field, enter a name to identify the ACL.
4. In the "Description" field, enter text to clarify the purpose of the ACL.
5. Click "Save".
6. Select the new ACL that was created and click it, which should open a Modify ACL dialog box.
7. Click "Add" to add an access control entry (ACE) to the ACL.
Each ACE consists of a combination of the network hosts and services that were configured for use in ACLs.
8. Use the following guidelines to complete the form:
Source Network
Destination Network
Service
Action - Select Permit or Deny from the dropdown list.
Connections Per Minute
9. Click "Save".
10. Configure Sentry with specified backend services such as Exchange Active Sync or App Tunnels. Refer to section "Configuring Standalone Sentry for ActiveSync" and "Configuring Standalone Sentry for AppTunnel" in "Sentry 9.8 Guide for MobileIron Core" to ensure these services are configured in Sentry settings in Core where applicable.
Review Sentry configuration to determine if it enforces approved authorizations for controlling the flow of management information within the network.
Sentry receives a request from MobileIron Core and enforces verification before handling the request to validate that it is from a trusted MobileIron Core.
Therefore, if the deployment uses MobileIron Core, to verify that Sentry trusts MobileIron Core in the deployment:
1. Run the following command in Sentry CLI:
show sentry EMM-source-verify
If this is set to "false", this is a finding.
2. Run the following command in Sentry CLI:
show sentry emm-ips
If the Core IP is not specified, this is a finding.
3. Verify Sentry has an ACL for Core in Sentry System Manager.
Then:
1. In the Standalone Sentry System Manager, go to Security >> Access Control Lists.
2. Verify that an ACL is created for Core. If it is not, this is a finding.
3. Determine if Sentry is configured with specified backend services such as Exchange Active Sync or App Tunnels.
If the backend service is not specified, this is a finding.
Refer to section "Configuring Standalone Sentry for ActiveSync" and "Configuring Standalone Sentry for AppTunnel" in "Sentry 9.8 Guide for MobileIron Core" to ensure these services are configured in Sentry settings in Core where applicable.
V-250985
False
MOIS-ND-000130
Review Sentry configuration to determine if it enforces approved authorizations for controlling the flow of management information within the network.
Sentry receives a request from MobileIron Core and enforces verification before handling the request to validate that it is from a trusted MobileIron Core.
Therefore, if the deployment uses MobileIron Core, to verify that Sentry trusts MobileIron Core in the deployment:
1. Run the following command in Sentry CLI:
show sentry EMM-source-verify
If this is set to "false", this is a finding.
2. Run the following command in Sentry CLI:
show sentry emm-ips
If the Core IP is not specified, this is a finding.
3. Verify Sentry has an ACL for Core in Sentry System Manager.
Then:
1. In the Standalone Sentry System Manager, go to Security >> Access Control Lists.
2. Verify that an ACL is created for Core. If it is not, this is a finding.
3. Determine if Sentry is configured with specified backend services such as Exchange Active Sync or App Tunnels.
If the backend service is not specified, this is a finding.
Refer to section "Configuring Standalone Sentry for ActiveSync" and "Configuring Standalone Sentry for AppTunnel" in "Sentry 9.8 Guide for MobileIron Core" to ensure these services are configured in Sentry settings in Core where applicable.
M
5438