IISW-SV-000119 - The IIS 8.5 web server must not be both a website server and a proxy server.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A web server should be primarily a web server or a proxy server but not both, for the same reasons that other multi-use servers are not recommended. Scanning for web servers that will also proxy requests into an otherwise protected network is a very common attack making the attack anonymous.

Solution

Open the IIS 8.5 Manager.

Under the 'Connections' pane on the left side of the management console, select the IIS 8.5 web server.

Under the IIS installed features, 'Application Request Routing Cache' is present, double-click the icon to open the feature.

From the right 'Actions' pane, under 'Proxy', select 'Server Proxy Settings...'.

In the 'Application Request Routing' settings window, remove the check from the 'Enable proxy' check box.

Click 'Apply' in the 'Actions' pane.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_8-5_Y23M04_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000381, Rule-ID|SV-214409r879587_rule, STIG-ID|IISW-SV-000119, STIG-Legacy|SV-91399, STIG-Legacy|V-76703, Vuln-ID|V-214409

Plugin: Windows

Control ID: 03a6330f629a2ca97319e8157b3060816547a8eb7fbb11fa36021d8ef605a6ad