The firewall must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services on the network segment in accordance as defined in the Ports, Protocols, and Services Management (PPSM) CAL and vulnerability assessments.

From Firewall Security Requirements Guide

Part of SRG-NET-000132-FW-000026

Associated with: CCI-000382

SV-94123r1_rule The firewall must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services on the network segment in accordance as defined in the Ports, Protocols, and Services Management (PPSM) CAL and vulnerability assessments.

Vulnerability discussion

Some ports, protocols, or services have well-known exploits or security weaknesses that can be leveraged in an attack against the enclave and put it at immediate risk. These ports, protocols, and services must be prohibited or restricted in the packet or stateful filtering firewall configuration in accordance with DoD policy. Policy filters restrict traffic destined to the enclave perimeter as defined in the PPSM CAL and vulnerability assessments.

Check content

Verify the firewall is configured to disable or restrict the use of functions, ports, protocols, and/or services on the network segment that are not allowed by the PPSM CAL and vulnerability assessments. Verify all applications used in the enclave are registered in the PPSM database. Review the vulnerability assessment for each port, protocol, and service allowed into the enclave and apply all appropriate mitigations defined in the Vulnerability Assessment report for that port, protocol, and service. Compare enabled functions, ports, and services with the PPSM requirements. If prohibited functions, ports, protocols, and services are enabled, this is a finding.

Fix text

SCAs must review the vulnerability assessment for each port, protocol, and service allowed into the enclave and apply all appropriate mitigations defined in the Vulnerability Assessment report. Register only ports, protocols, and functions allowed into the enclave in the PPSM database. The enclave owner must register the applications used in the PPSM database. Consult the packet/stateful firewall knowledge base and configuration guides to determine the commands for disabling each port, protocol, service, or function that is not in compliance.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer