WN12-SO-000042 - IPSec Exemptions must be limited.

Information

IPSec exemption filters allow specific traffic that may be needed by the system for such things as Kerberos authentication. This setting configures Windows for specific IPSec exemptions.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic' to 'Only ISAKMP is exempt (recommended for Windows Server 2003)'.

(See 'Updating the Windows Security Options File' in the STIG Overview document if MSS settings are not visible in the system's policy tools.)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-226306r794597_rule, STIG-ID|WN12-SO-000042, STIG-Legacy|SV-52945, STIG-Legacy|V-14232, Vuln-ID|V-226306

Plugin: Windows

Control ID: 81f09e6c311d3e55f843e88adf3ba78ae209467a9df96b2ea4d4fedae5fa94da