NET-SRVFRM-003 - Server VLAN interfaces must be protected by restrictive ACLs using a deny-by-default security posture.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Protecting data sitting in a server VLAN is necessary and can be accomplished using access control lists on VLANs provisioned for servers. Without proper access control of traffic entering or leaving the server VLAN, potential threats such as a denial of service, data corruption, or theft could occur, resulting in the inability to complete mission requirements by authorized users.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure an ACL to protect the server VLAN interface. The ACL must be in a deny-by-default security posture.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5), CAT|II, Rule-ID|SV-20061r3_rule, STIG-ID|NET-SRVFRM-003, Vuln-ID|V-18522

Plugin: Juniper

Control ID: 589fc52fd2c71427ac850418d60ca72c1efda144ce599e3709063f1e7cc4c808