STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry must only allow incoming communications from organization-defined authorized sources routed to organization-defined authorized destinations.

DISA Rule

SV-251034r1028200_rule

Vulnerability Number

V-251034

Group Title

SRG-NET-000364-ALG-000122

Rule Version

MOIS-AL-001000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure only approved network routes on the Sentry.

1. Log in to Sentry System Manager.
2. Go to Settings >> Routes.
3. Select any unauthorized network routes in the list and click "Delete".
4. Click "Add" to add approved routes.

Check Contents

Verify only approved network routes are added to the Sentry.

1. Log in to Sentry System Manager.
2. Go to Settings >> Network >> Routes.
3. Verify only approved network routes are configured.

If non-approved network routes are configured, this is a finding.

Vulnerability Number

V-251034

Documentable

False

Rule Version

MOIS-AL-001000

Severity Override Guidance

Verify only approved network routes are added to the Sentry.

1. Log in to Sentry System Manager.
2. Go to Settings >> Network >> Routes.
3. Verify only approved network routes are configured.

If non-approved network routes are configured, this is a finding.

Check Content Reference

M

Target Key

5439