SV-282680r1201020_rule
V-282680
SRG-OS-000480-GPOS-00227
TOSS-05-000206
CAT II
10
Remove all unapproved tunnels from the system or document them with the ISSO.
Verify TOSS 5 does not have unauthorized IP tunnels configured.
Determine if the "IPsec" service is active using the following command:
$ systemctl status ipsec
ipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec
Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled)
Active: inactive (dead)
If the "IPsec" service is active, check for configured IPsec connections ("conn"), using the following command:
$ grep -rni conn /etc/ipsec.conf /etc/ipsec.d/
Verify any returned results are documented with the ISSO.
If the IPsec tunnels are active and not approved, this is a finding.
V-282680
False
TOSS-05-000206
Verify TOSS 5 does not have unauthorized IP tunnels configured.
Determine if the "IPsec" service is active using the following command:
$ systemctl status ipsec
ipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec
Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled)
Active: inactive (dead)
If the "IPsec" service is active, check for configured IPsec connections ("conn"), using the following command:
$ grep -rni conn /etc/ipsec.conf /etc/ipsec.d/
Verify any returned results are documented with the ISSO.
If the IPsec tunnels are active and not approved, this is a finding.
M
5738