7.4 Ensure the 'addressIncludeList' attribute is set to a whitelist of IP addresses

Information

IP addresses can be allowed or blocked from creating inbound TCP connections to different HTTP endpoints.

Defining an IP address include list allows only wanted inbound connections.

Solution

Add the addressIncludeList attribute to all tcpOptions elements to ${server.config.dir}/configDropins/overrides/*.xml and set to comma-separated list of IP Address.

<tcpOptions addressIncludeList="254.*.*.9,255.0.0.2" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(8), CSCv7|9.5

Plugin: Unix

Control ID: f50a9cf6d8dee5abfd31d979a78ce3bbc52300e885e119f3dafa614b1b3aebf7