GEN005580 - A system used for routing must not run other network services or applications.

Information

Installing extraneous software on a system designated as a dedicated router poses a security threat to the system and the network. Should an attacker gain access to the router through the unauthorized software, the entire network is susceptible to malicious activity.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure only authorized software is loaded on a designated router. Authorized software will be limited to the most current version of routing protocols and SSH for system administration purposes.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001208, Rule-ID|SV-64109r2_rule, STIG-ID|GEN005580, Vuln-ID|V-4398

Plugin: Unix

Control ID: 2f61327e241358e785f08374da6381ebea449006abe089559cb1a2571888e4d7