The AAA Service must be configured to place non-authenticated network access requests in the Unauthorized VLAN or the Guest VLAN with limited access.

From Authentication Authorization and Accounting Service Security Requirements Guide

Part of SRG-APP-000516-AAA-000066

Associated with: CCI-000366

SRG-APP-000516-AAA-000066_rule The AAA Service must be configured to place non-authenticated network access requests in the Unauthorized VLAN or the Guest VLAN with limited access.

Vulnerability discussion

Devices having an IP address that do not pass authentication can be used to attack compliant devices if they share VLANs. When devices proceed into the NAC AAA (radius) functions they must originate in the Unauthorized VLAN by default. If the device fails authentication it should be denied IP capability and movement to other dynamic VLANs used in the NAC process flow or moved to a VLAN that has limited capability such as a Guest VLAN with internet access, but without access to production assets.

Check content

If the AAA Service is not used to authenticate privileged users for device management, this is not applicable. Verify the AAA Service is configured to place non-authenticated network access requests in the Unauthorized VLAN or the Guest VLAN with limited access. If the SA has created a dynamic Unauthorized VLAN, definitions should not have an IP pool assignment. Ensure the Unauthorized VLAN is configured without IP or a Guest VLAN is defined with limited access. If the AAA Service is not configured to place non-authenticated network access requests in the Unauthorized VLAN or the Guest VLAN with limited access, this is a finding.

Fix text

Configure the AAA Service to place non-authenticated network access requests in the Unauthorized VLAN without access to production data. Implement a NAC solution where the device remains without IP assignment if authentication fails or create a dynamic Unauthorized VLAN / Guest VLAN with limited access in AAA server. If a Guest VLAN is built, it should not have access to production data.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer