2.8.7 Ensure 'Enable the use of relay servers by the remote access host' is set to 'Disabled'.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Google Chrome allows the use relay servers when clients are trying to connect to this machine and a direct connection is not available.

Disable (0): The use of relay servers by the remote access host in not allowed

Enabled (1): The use of relay servers by the remote access host is allowed

The recommended state for this setting is: Disabled (0)

Rationale:

Relay servers shall not be used to circumvent firewall restrictions.

Impact:

If this setting is disabled, remote clients can not use relay servers to connect to this machine.

NOTE: Setting this to Disabled doesn't turn remote access off, but only allows connections from the same network (not NAT traversal or relay).

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:

Computer Configuration\Polices\Administrative Templates\Google\Google Chrome\Remote access\Enable the use of relay servers by the remote access host

Default Value:

Unset (Same as Enabled, but user can change)

See Also

https://workbench.cisecurity.org/files/3653