NET0377 - The firewall must not utilize any services or capabilities that are not necessary for the administration of the firewall.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The risk of an attack increases with more services enabled on the firewall, since the firewall will listen for these services. If non-firewall services (e.g., DNS servers, e-mail client servers, ftp servers, web servers, etc.) are part of the standard firewall suite and are not necessary for administration of the firewall, they will be uninstalled or disabled.

NOTE: Nessus did not perform this check as manual review is required. Verify all non-essential features are removed from the firewall.

Solution

The Firewall Administrator will only utilize services related to the operation of the firewall. Any unnecessary services, even if they are part of the firewall standard suite, must be uninstalled or disabled.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R24_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-3054r3_rule, STIG-ID|NET0377, Vuln-ID|V-3054

Plugin: Cisco

Control ID: 57b855fcb4e353aa343e3ef708b4722073087ee8558b5491e62addbbdec02ad2