NET-TUNL-007 - Tunnel entry and exit points must be in a deny-by-default security posture.

Information

Having tunnels in a permit any any posture allow traffic to enter and exit the enclave without control from the Information Assurance team or SA.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Apply a deny by default posture on every tunnel end-point.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5), CAT|II, Rule-ID|SV-20240r2_rule, STIG-ID|NET-TUNL-007, Vuln-ID|V-18648

Plugin: Juniper

Control ID: 110d2ff39b58c719cf52d8cc700cae096765a5fb9d1e6da31ac1dfb4c60d694e