SV-279692r1155075_rule
V-279692
SRG-APP-000039
OKTA-APP-003243
CAT II
10
From the Admin Console:
1. Select the "Security" menu, and then click the "Networks" item.
2. If the CSSP has provided a list of anonymizers to block, add the IP ranges to the "IP Block list".
a. Click the pencil icon next to IP Block list.
b. Add the IP ranges to the "Gateway IPs" section and click "Save".
3. If the CSSP is not able to provide a list, then implement the Okta managed list.
a. Set the "Enhanced dynamic zone blocklist" to "Active".
From the Admin Console:
1. Select the "Security" menu, and then click the "Networks' item.
2. If the CSSP has provided a list of anonymizers to block, verify the "IP Block list" is configured with them.
a. Click the pencil icon next to IP Block list.
b. Verify the "Gateway IPs" section contains all of the IP ranges in the provided list.
3. If the CSSP is not able to provide a list, then implement the Okta managed list.
a. Verify the "Enhanced dynamic zone blocklist" is set to "Active".
If Network Zones are not configured to block anonymous proxies, this is a finding.
V-279692
False
OKTA-APP-003243
From the Admin Console:
1. Select the "Security" menu, and then click the "Networks' item.
2. If the CSSP has provided a list of anonymizers to block, verify the "IP Block list" is configured with them.
a. Click the pencil icon next to IP Block list.
b. Verify the "Gateway IPs" section contains all of the IP ranges in the provided list.
3. If the CSSP is not able to provide a list, then implement the Okta managed list.
a. Verify the "Enhanced dynamic zone blocklist" is set to "Active".
If Network Zones are not configured to block anonymous proxies, this is a finding.
M
5694