NET0988 - Traffic from the managed network will leak - 'OOBM Interface (ip access-list OOBM_EGRESS_ACL out)'

Information

Traffic from the managed network will leak into the management network via the gateway router interface connected to the OOBM backbone.

If the gateway router is not a dedicated device for the OOBM network, several safeguards must be implemented for containment of management and production traffic boundaries such as using interface ACLs or filters at the boundaries between the two networks.

NOTE: Change 'OOBM_INTERFACE' to the OOBM interface for your organization.
NOTE: Change 'OOBM_EGRESS_ACL' to the ACL list for granting your organization's management network access to the router and to prevent the managed network from leaking into the management network.

Solution

Configure the OOBM gateway router interface ACLs to ensure traffic from the managed network does not leak into the management network.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(15), CAT|II, Rule-ID|SV-19303r1_rule, STIG-ID|NET0988, Vuln-ID|V-17818

Plugin: Cisco

Control ID: 3e6b53fa4f4b2fc55d6fd906e8a08f12bdd0844c75cdbdd890fa307ba0f2eb3a