3.127 - IPSec Exemptions are limited.

Information

This check verifies that Windows is configured to limit IPSec exemptions.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> 'MSS- (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic' to 'Multicast, broadcast and ISAKMP exempt (best for Windows XP)'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip