From Firewall Security Requirements Guide
Part of SRG-NET-000364-FW-000033
Associated with: CCI-002403
The firewall must reject requests for access or services where the source address received by the firewall specifies a loopback address. The loopback address is used by an Inter-Processor Control (IPC) mechanism that enables the client and server portion of an application running on the same machine to communicate, and so it is trusted. It should never be used as the source IP address of an inbound or outbound transmission.
Review the device configuration to determine if filters are in place to block loopback addresses. Verify packets with a destination IP address assigned to the management or loopback address range are blocked (unless the packet has a source address assigned to the management network or network infrastructure). If loopback addresses are not being blocked by an ingress firewall filter, this is a finding.
Establish ingress filters to block any attempt from the firewall or any network to pass any packets claiming to be from a loopback address.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer