STIGQter STIGQter: STIG Summary: IBM DataPower ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Jan 2016:

The DataPower Gateway providing content filtering must not have a front side handler configured facing an internal network.

DISA Rule

SV-79721r1_rule

Vulnerability Number

V-65231

Group Title

SRG-NET-000192-ALG-000121

Rule Version

WSDP-AG-000045

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the initial Web interface screen (the Control Panel), select Objects >> Protocol Handlers >> HTTPS Front Side Handler.

Click on each of the Handlers in the list that appears >> Click the Advanced tab of the Handler configuration.

For the Access Control List field, click “+” to create a new ACL >> Enter a name for the List >> Click the Entry tab >> Click Add >> Select Deny and set the Address Range to network segments representing internal networks >> Click Apply.

Check Contents

From the initial Web interface screen (the Control Panel), select Objects >> Protocol Handlers >>HTTPS Front Side Handler.

Click on each of the Handlers in the list that appears >> Click the Advanced tab of the Handler configuration >> Verify that there is an Access Control List selected >> Click the ellipses (…) button beside the list.

On the Access Control List page, click the Entry tab >> Verify that the network segments representing internal networks are denied.

If these items are not configured, this is a finding.

Vulnerability Number

V-65231

Documentable

False

Rule Version

WSDP-AG-000045

Severity Override Guidance

From the initial Web interface screen (the Control Panel), select Objects >> Protocol Handlers >>HTTPS Front Side Handler.

Click on each of the Handlers in the list that appears >> Click the Advanced tab of the Handler configuration >> Verify that there is an Access Control List selected >> Click the ellipses (…) button beside the list.

On the Access Control List page, click the Entry tab >> Verify that the network segments representing internal networks are denied.

If these items are not configured, this is a finding.

Check Content Reference

M

Target Key

2859

Comments