GEN008540 - The system's local firewall must implement a deny-all, allow-by-exception policy

Information

A local firewall protects the system from exposing unnecessary or undocumented network services to the local enclave. If a system within the enclave is compromised, firewall protection on an individual system continues to protect it from attack.

Solution

Edit /etc/opt/ipf/ipf.conf and add a default deny rule and restart the ipfilter service.
# /sbin/init.d/ipfboot stop
# /sbin/init.d/ipfboot start

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001109, CSCv6|9.2, Rule-ID|SV-26977r1_rule, STIG-ID|GEN008540, Vuln-ID|V-22583

Plugin: Unix

Control ID: 2c8b3d70e70bcfb1bd89ce9e2d5981d443d7a893062a25f85099c68517bdccee