GEN005580 - A system used for routing must not run other network services or applications.

Information

Installing extraneous software on a system designated as a dedicated router poses a security threat to the system and the network. Should an attacker gain access to the router through the unauthorized software, the entire network is susceptible to malicious activity.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure only authorized software is loaded on a designated router. Authorized software will be limited to the most current version of routing protocols and SSH for system administration purposes.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-7a., 800-53|SC-32, CAT|II, CCI|CCI-000381, CCI|CCI-001208, Rule-ID|SV-218621r603259_rule, STIG-ID|GEN005580, STIG-Legacy|SV-64109, STIG-Legacy|V-4398, Vuln-ID|V-218621

Plugin: Unix

Control ID: f0dc2fbceccbbecacc928bbda061c27056ba95ee8c6bdc1d8d02ff4915e2c562