NET0988 - Traffic from the managed network will leak into the management network - OOBM Interface

Information

If the gateway router is not a dedicated device for the OOBM network, several safeguards must be implemented for containment of management and production traffic boundaries such as using interface ACLs or filters at the boundaries between the two networks.

Solution

Configure the OOBM gateway router interface ACLs to ensure traffic from the managed network does not leak into the management network.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11), CAT|II, Rule-ID|SV-19304r1_rule, STIG-ID|NET0988, Vuln-ID|V-17818

Plugin: Juniper

Control ID: a830cdfa86f3fcb9ece16646a11573f30c350d468512d6f34f513f99c0df3f1f