STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Firewall rules must be configured on the Tanium Server for Server-to-Zone Server communications.

DISA Rule

SV-253858r997280_rule

Vulnerability Number

V-253858

Group Title

SRG-APP-000383

Rule Version

TANS-SV-000033

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Configure host-based firewall rules on the Tanium Zone server to include the following required traffic:

Allow Tanium Server to Zone Server over TCP port 17472.

2. Configure the network firewall to allow the above traffic.

Note: By default, the Zone Server uses 17472 for traffic from Zone Server Hubs and Tanium Clients. However, as a best practice to improve the security of the Zone Server, different ports can be configured for the hubs and clients.

Check Contents

Note: If a Zone Server is not being used, this is not applicable.

Consult with the Tanium system administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.

1. Access the Tanium Server.

2. Log on to the server with an account that has administrative privileges.

3. Access the host-based firewall configuration on the Tanium Server.

4. Validate a rule exists for the following:

Port Needed: Tanium Server to Zone Server over TCP port 17472.

Note: By default, the Zone Server uses 17472 for traffic from Zone Server Hubs and Tanium Clients. However, as a best practice to improve the security of the Zone Server, different ports can be configured for the hubs and clients.

If a host-based firewall rule does not exist to allow TCP port 17472 or other defined port, bidirectionally, from the Tanium Server to the Tanium Zone Server, this is a finding.

Vulnerability Number

V-253858

Documentable

False

Rule Version

TANS-SV-000033

Severity Override Guidance

Note: If a Zone Server is not being used, this is not applicable.

Consult with the Tanium system administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.

1. Access the Tanium Server.

2. Log on to the server with an account that has administrative privileges.

3. Access the host-based firewall configuration on the Tanium Server.

4. Validate a rule exists for the following:

Port Needed: Tanium Server to Zone Server over TCP port 17472.

Note: By default, the Zone Server uses 17472 for traffic from Zone Server Hubs and Tanium Clients. However, as a best practice to improve the security of the Zone Server, different ports can be configured for the hubs and clients.

If a host-based firewall rule does not exist to allow TCP port 17472 or other defined port, bidirectionally, from the Tanium Server to the Tanium Zone Server, this is a finding.

Check Content Reference

M

Target Key

5476