SV-254944r961470_rule
V-254944
SRG-APP-000383
TANS-AP-000985
CAT II
10
1. Configure host-based firewall rules on the Tanium Zone server to include the following required traffic:
1A. Allow Tanium Server to Zone Server over TCP port 17472.
2. Configure the network firewall to allow the above traffic.
Note: By default, the Zone Server uses 17472 for traffic from Zone Server Hubs and Tanium Clients. However, as a best practice to improve the security of the Zone Server, different ports can be configured for the hubs and clients.
Note: If a Zone Server is not being used, this is Not Applicable.
Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.
1. Access the Tanium Server interactively.
2. Log on to the server with an account that has administrative privileges.
3. Access the host-based firewall configuration on the Tanium Server.
4. Validate a rule exists for the following:
4A. Port Needed: Tanium Server to Zone Server over TCP port 17472.
Note: By default, the Zone Server uses 17472 for traffic from Zone Server Hubs and Tanium Clients. However, as a best practice to improve the security of the Zone Server, different ports can be configured for the hubs and clients.
If a host-based firewall rule does not exist to allow TCP port 17472 or other defined port, bidirectionally, from Tanium Server to the Tanium Zone Server, this is a finding.
V-254944
False
TANS-AP-000985
Note: If a Zone Server is not being used, this is Not Applicable.
Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.
1. Access the Tanium Server interactively.
2. Log on to the server with an account that has administrative privileges.
3. Access the host-based firewall configuration on the Tanium Server.
4. Validate a rule exists for the following:
4A. Port Needed: Tanium Server to Zone Server over TCP port 17472.
Note: By default, the Zone Server uses 17472 for traffic from Zone Server Hubs and Tanium Clients. However, as a best practice to improve the security of the Zone Server, different ports can be configured for the hubs and clients.
If a host-based firewall rule does not exist to allow TCP port 17472 or other defined port, bidirectionally, from Tanium Server to the Tanium Zone Server, this is a finding.
M
5492