STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Firewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server.

DISA Rule

SV-253856r1099953_rule

Vulnerability Number

V-253856

Group Title

SRG-APP-000383

Rule Version

TANS-SV-000031

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Configure host-based firewall rules on the Tanium Module Server to include the following required traffic:

Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server.

2. Configure the network firewall to allow the above traffic.

Check Contents

Consult with the Tanium system administrator to verify which firewall is being used as a host-based firewall on the Tanium Module Server.

1. Access the Tanium Server.

2. Log on to the server with an account that has administrative privileges.

3. Access the host-based firewall configuration on the Tanium Module Server.

4. Validate a rule exists for the following:

Port Needed: Tanium Server to Tanium Module Server over TCP port 17477.

If a host-based firewall rule does not exist to allow TCP port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.

Consult with the network firewall administrator and validate rules exist for the following:

Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server.

If a network firewall rule does not exist to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.

Vulnerability Number

V-253856

Documentable

False

Rule Version

TANS-SV-000031

Severity Override Guidance

Consult with the Tanium system administrator to verify which firewall is being used as a host-based firewall on the Tanium Module Server.

1. Access the Tanium Server.

2. Log on to the server with an account that has administrative privileges.

3. Access the host-based firewall configuration on the Tanium Module Server.

4. Validate a rule exists for the following:

Port Needed: Tanium Server to Tanium Module Server over TCP port 17477.

If a host-based firewall rule does not exist to allow TCP port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.

Consult with the network firewall administrator and validate rules exist for the following:

Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server.

If a network firewall rule does not exist to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.

Check Content Reference

M

Target Key

5476