STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

Firewall rules must be configured on the Tanium Server for Client-to-Server communications.

DISA Rule

SV-254906r1043177_rule

Vulnerability Number

V-254906

Group Title

SRG-APP-000142

Rule Version

TANS-AP-000360

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Consult with the personnel who maintain the Enterprise Security Suite to configure host-based and network firewall rules to allow the following:

1A. Tanium Clients or Zone Clients over TCP port 17472, bi-directionally.

2. Consult with the boundary network firewall administrator to create a rule to allow the following:

2A. TCP traffic on port 17472 from any computer to be managed on a local area network to any other computer to be managed on the same local area network.

Check Contents

Note: This check is performed for the Tanium Endpoints and must be validated against the enterprise firewall solution (e.g., Endpoint Security Solution Firewall, Microsoft Windows Defender Firewall setting, Microsoft Advance Threat Protection Firewall, etc.) policies applied to the Endpoints.

1. Consult with the personnel who maintain the Enterprise Security Suite configuration for assistance.

2. Validate a rule exists within the firewall policies for managed clients for the following:

2A. Port Needed: Tanium Clients or Zone Clients over TCP port 17472, bi-directionally.

If a host-based firewall rule does not exist to allow TCP port 17472, bi-directionally, this is a finding.

3. Consult with the boundary network firewall administrator and validate rules exist for the following:

3A. Allow TCP traffic on port 17472 from any computer to be managed on a local area network to any other computer to be managed on the same local area network.

If a network firewall rule does not exist to allow TCP port 17472 from any managed computer to any other managed computer on the same local area network, this is a finding.

Vulnerability Number

V-254906

Documentable

False

Rule Version

TANS-AP-000360

Severity Override Guidance

Note: This check is performed for the Tanium Endpoints and must be validated against the enterprise firewall solution (e.g., Endpoint Security Solution Firewall, Microsoft Windows Defender Firewall setting, Microsoft Advance Threat Protection Firewall, etc.) policies applied to the Endpoints.

1. Consult with the personnel who maintain the Enterprise Security Suite configuration for assistance.

2. Validate a rule exists within the firewall policies for managed clients for the following:

2A. Port Needed: Tanium Clients or Zone Clients over TCP port 17472, bi-directionally.

If a host-based firewall rule does not exist to allow TCP port 17472, bi-directionally, this is a finding.

3. Consult with the boundary network firewall administrator and validate rules exist for the following:

3A. Allow TCP traffic on port 17472 from any computer to be managed on a local area network to any other computer to be managed on the same local area network.

If a network firewall rule does not exist to allow TCP port 17472 from any managed computer to any other managed computer on the same local area network, this is a finding.

Check Content Reference

M

Target Key

5492