3.7 Ensure no Allow Rule with Any in Services filed present in the Firewall Rules

Information

The Firewall Rules with Any in the Service field allows accessing all the Services from specified Source to specified Destination configured in the Firewall rules.

Rationale:

There are many services like telnet, FTP, TFTP which are having many security issues. Hackers can take advantage of these services to gain the credentials, access to the systems or they can use these services for DoS attacks. These services need to be configured as per the needs of the business.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Delete the rule from the firewall which has Any used in the Service field.

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-2, CSCv7|11.1

Plugin: CheckPoint

Control ID: 4b25a586024666efbb9ab28650b5c835fb0da9ff7fade631f0b3594c0c136fc7