STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.

DISA Rule

SV-250985r1028212_rule

Vulnerability Number

V-250985

Group Title

SRG-APP-000038-NDM-000213

Rule Version

MOIS-ND-000130

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure Sentry to enforce approved authorizations for controlling the flow of management information within the network device.

Sentry receives a request from MobileIron Core and enforces verification before handling the request to validate that it is from a trusted MobileIron Core.

Therefore, if the deployment uses MobileIron Core, to ensure that Sentry trusts MobileIron Core in the deployment, run the following commands in Sentry CLI:

1. sentry emm-source-verify true

2. sentry emm-ips <subnet_list>>

3. This can further be mitigated by creating ACLs for Sentry System Manager.

Then:
1. In the Standalone Sentry System Manager, go to Security >> Access Control Lists.
2. Click "Add".
3. In the "Name" field, enter a name to identify the ACL.
4. In the "Description" field, enter text to clarify the purpose of the ACL.
5. Click "Save".
6. Select the new ACL that was created and click it, which should open a Modify ACL dialog box.
7. Click "Add" to add an access control entry (ACE) to the ACL.
Each ACE consists of a combination of the network hosts and services that were configured for use in ACLs.
8. Use the following guidelines to complete the form:
Source Network
Destination Network
Service
Action - Select Permit or Deny from the dropdown list.
Connections Per Minute
9. Click "Save".
10. Configure Sentry with specified backend services such as Exchange Active Sync or App Tunnels. Refer to section "Configuring Standalone Sentry for ActiveSync" and "Configuring Standalone Sentry for AppTunnel" in "Sentry 9.8 Guide for MobileIron Core" to ensure these services are configured in Sentry settings in Core where applicable.

Check Contents

Review Sentry configuration to determine if it enforces approved authorizations for controlling the flow of management information within the network.

Sentry receives a request from MobileIron Core and enforces verification before handling the request to validate that it is from a trusted MobileIron Core.

Therefore, if the deployment uses MobileIron Core, to verify that Sentry trusts MobileIron Core in the deployment:

1. Run the following command in Sentry CLI:
show sentry EMM-source-verify

If this is set to "false", this is a finding.

2. Run the following command in Sentry CLI:
show sentry emm-ips

If the Core IP is not specified, this is a finding.

3. Verify Sentry has an ACL for Core in Sentry System Manager.

Then:
1. In the Standalone Sentry System Manager, go to Security >> Access Control Lists.
2. Verify that an ACL is created for Core. If it is not, this is a finding.
3. Determine if Sentry is configured with specified backend services such as Exchange Active Sync or App Tunnels.

If the backend service is not specified, this is a finding.

Refer to section "Configuring Standalone Sentry for ActiveSync" and "Configuring Standalone Sentry for AppTunnel" in "Sentry 9.8 Guide for MobileIron Core" to ensure these services are configured in Sentry settings in Core where applicable.

Vulnerability Number

V-250985

Documentable

False

Rule Version

MOIS-ND-000130

Severity Override Guidance

Review Sentry configuration to determine if it enforces approved authorizations for controlling the flow of management information within the network.

Sentry receives a request from MobileIron Core and enforces verification before handling the request to validate that it is from a trusted MobileIron Core.

Therefore, if the deployment uses MobileIron Core, to verify that Sentry trusts MobileIron Core in the deployment:

1. Run the following command in Sentry CLI:
show sentry EMM-source-verify

If this is set to "false", this is a finding.

2. Run the following command in Sentry CLI:
show sentry emm-ips

If the Core IP is not specified, this is a finding.

3. Verify Sentry has an ACL for Core in Sentry System Manager.

Then:
1. In the Standalone Sentry System Manager, go to Security >> Access Control Lists.
2. Verify that an ACL is created for Core. If it is not, this is a finding.
3. Determine if Sentry is configured with specified backend services such as Exchange Active Sync or App Tunnels.

If the backend service is not specified, this is a finding.

Refer to section "Configuring Standalone Sentry for ActiveSync" and "Configuring Standalone Sentry for AppTunnel" in "Sentry 9.8 Guide for MobileIron Core" to ensure these services are configured in Sentry settings in Core where applicable.

Check Content Reference

M

Target Key

5438