STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for mobile device sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity.

DISA Rule

SV-251029r1028195_rule

Vulnerability Number

V-251029

Group Title

SRG-NET-000213-ALG-000107

Rule Version

MOIS-AL-000470

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Sentry to terminate all network connections associated with a communication session at 15 minutes of inactivity.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Configurations.
3. Click on existing VPN Configuration for MobileIron Tunnel; ensure "Connection Type" is set to "MobileIron Tunnel".
4. Go to "Custom Data" section at the bottom and find the following Key Value pair: "TcpIdleTmoMs"

If the key value pair is present, set the value to 900000 millisec (15 min).

Check Contents

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Configurations.
3. Click on existing VPN Configuration for MobileIron Tunnel; verify "Connection Type" is set to "MobileIron Tunnel".
4. Go to "Custom Data" section at the bottom and find the following Key Value pair: "TcpIdleTmoMs"

The default idle timeout for the session is 1 hour. Therefore, if the key value pair is missing, this is a finding.

If the key value pair is present, verify the value is no greater than 900000 millisec (15 min).

If key value pair is not present or is set to a value greater than 900000, this is a finding.

Vulnerability Number

V-251029

Documentable

False

Rule Version

MOIS-AL-000470

Severity Override Guidance

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Configurations.
3. Click on existing VPN Configuration for MobileIron Tunnel; verify "Connection Type" is set to "MobileIron Tunnel".
4. Go to "Custom Data" section at the bottom and find the following Key Value pair: "TcpIdleTmoMs"

The default idle timeout for the session is 1 hour. Therefore, if the key value pair is missing, this is a finding.

If the key value pair is present, verify the value is no greater than 900000 millisec (15 min).

If key value pair is not present or is set to a value greater than 900000, this is a finding.

Check Content Reference

M

Target Key

5439