Firewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server.

From Tanium 6.5 Security Technical Implementation Guide

Part of SRG-APP-000383

Associated with: CCI-001762

SV-81593r1_rule Firewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server.

Vulnerability discussion

Tanium 6.5 introduces the Tanium Module Server (formerly known as the Tanium Plugin Server) used to extend the functionality of Tanium through the use of various workbenches. The Tanium Module Server requires communication with the Tanium Server on port 17477.https://kb.tanium.com/Port_Configuration_v6.5

Check content

Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Module Server. Access the host-based firewall configuration on the Tanium Module Server. Validate a rule exists for the following: Port Needed: Tanium Server to Tanium Module Server over TCP port 17477. If a host-based firewall rule does not exist to allow TCP port 17477, from the Tanium Server to the Tanium Module Server, this is a finding. Consult with the network firewall administrator and validate rules exist for the following: Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server. If a network firewall rule does not exist to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.

Fix text

Configure host-based firewall rules on the Tanium Module server to include the following required traffic: Allow TCP traffic on port 17477 from the Tanium Server. Configure the network firewall to allow the above traffic.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer