3.127 - IPSec Exemptions are limited.

Information

This check verifies that Windows is configured to limit IPSec exemptions.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'MSS- (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic' to 'Multicast, broadcast and ISAKMP exempt (best for Windows XP)'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-14843r1_rule, STIG-ID|3.127, Vuln-ID|V-14232

Plugin: Windows

Control ID: 93c0f3fd36c5d4b34d5f1708a2cef10e0f82d6413f22aec9fe97ca6edbc3c9a2