Firewall rules must be configured on the Tanium Server for Console-to-Server communications.

From Tanium 6.5 Security Technical Implementation Guide

Part of SRG-APP-000383

Associated with: CCI-001762

SV-81511r1_rule Firewall rules must be configured on the Tanium Server for Console-to-Server communications.

Vulnerability discussion

An HTML5/Adobe Flash based application, the Tanium Console runs from any device with a browser configured with Adobe Flash Player 11.5 or higher. For security, the TCP and SOAP communication to the Tanium Server is SSL encrypted, so the Tanium Server installer configures the server to listen for TCP and SOAP requests on port 443. If another installed application is listening on port 443, you can designate a different port for TCP and SOAP communication when installing the Tanium Server.Port Needed: To Tanium Server over TCP ports 443, 17440, and 17441Network firewall rules:Allow TCP traffic on port 443 from any computer on the internal network to the Tanium Server deviceAllow TCP traffic on port 17440 from any computer on the internal network to the Tanium Server device (Patch Workbench)https://kb.tanium.com/Port_Configuration_v6.5

Check content

Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server. Access the host-based firewall configuration on the Tanium Server. Validate a rule exists for the following: Port Needed: From only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441. If a host-based firewall rule does not exist to allow only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441, this is a finding. Consult with the network firewall administrator and validate rules exist for the following: Allow TCP traffic from only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441. If a network firewall rule does not exist to allow traffic from only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441, this is a finding.

Fix text

Configure host-based and network firewall rules as required.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer