GEN005580 - A system used for routing must not run other network services or applications.

Information

Installing extraneous software on a system designated as a dedicated router poses a security threat to the system and the network. Should an attacker gain access to the router through the unauthorized software, the entire network is susceptible to malicious activity.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure only authorized software is loaded on a designated router. Authorized software will be limited to the most current version of routing protocols and SSH for system administration purposes.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-32, CAT|II, CCI|CCI-001208, Group-ID|V-4398, Rule-ID|SV-37924r2_rule, STIG-ID|GEN005580, Vuln-ID|V-4398

Plugin: Unix

Control ID: d755dab5aab72131a64cebe3e3e1c4d65fb4465a3765c0852b692b55488eff31