GEN005580 - A system used for routing must not run other network services or applications

Information

If a system has no default gateway defined, the system is at increased risk of man-in-the-middle, monitoring, and Denial of Service attacks.

Solution

Ensure only authorized software is loaded on a designated router. Authorized software will be limited to the most current version of routing protocols and SSH for system administration purposes.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-4, 800-53|SC-5, CAT|II, CCI|CCI-001208, Rule-ID|SV-35156r1_rule, STIG-ID|GEN005580, Vuln-ID|V-4398

Plugin: Unix

Control ID: cd96d1e53e48b18e3818e0227b449eea3cbb43b881f34d27b6176e6881d573bb