CSCv7|12.4

Title

Deny Communication over Unauthorized Ports

Description

Deny communication over unauthorized TCP or UDP ports or application traffic to ensure that only authorized protocols are allowed to cross the network boundary in or out of the network at each of the organization's network boundaries.

Reference Item Details

Category: Boundary Defense

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.4.4.2 Enable listening ports range is set as appropriate for organizationZoomCIS Zoom L2 v1.0.0
1.2.3 SSH Server Port CustomizationArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
1.2.7 Disable the Telnet FeatureCiscoCIS Cisco NX-OS v1.2.0 L1
1.9 CISC-RT-000150CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
1.10 CISC-RT-000160CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT III
1.11 CISC-RT-000170CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
1.12 CISC-RT-000190CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
1.22 CISC-RT-000350CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
1.23 CISC-RT-000360CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT III
1.24 CISC-RT-000370CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT III
1.25 CISC-RT-000380CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
1.59 CISC-RT-000790CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
1.60 CISC-RT-000800CiscoCIS Cisco NX OS Switch RTR STIG v1.1.0 CAT II
2.1 Ensure 'Protect RE' Firewall Filter is set for inbound traffic to the Routing EngineJuniperCIS Juniper OS Benchmark v2.1.0 L1
2.1.8 Disable static keys for TLSFortiGateCIS FortiGate 7.4.x v1.0.1 L2
2.4 IP Directed BroadcastArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.1.1.1 OSPF Passive InterfacesArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.1.2.3 BGP TTL SecurityArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.2 Configure a Default Drop/Cleanup RuleCheckPointCIS Check Point Firewall L2 v1.1.0
3.2.1.1 DHCPv4 & DHCPv6 Snooping EnablementArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.2.1.2 DHCPv6 GuardArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.3.8 Multicast BSR BoundaryArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.5 Dynamic ARP InspectionArubaOSCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security Recommendations
3.6 Ensure That SSH Access Is Restricted From the InternetGCPCIS Google Cloud Platform Foundation v5.0.0 L2
3.7 Ensure That RDP Access Is Restricted From the InternetGCPCIS Google Cloud Platform Foundation v5.0.0 L2
4.2 Ensure 'Applications and Threats Update Schedule' is set to download and install updates at daily or shorter intervalsPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
4.6.18.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v5.0.0 L1
4.6.18.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v5.0.0 L1
5.1 Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly AccessibleGCPCIS Google Cloud Platform Foundation v5.0.0 L1
5.2.12 Minimize the admission of containers which use HostPortsUnixCIS Kubernetes v2.0.1 L1 Master Node
5.3 Ensure port lockdown for self IP is setF5CIS F5 Networks v1.0.0 L1
5.6 (L1) Host should reject forged transmits on standard virtual switches and port groupsVMwareCIS VMware ESXi 8.0 v1.3.0 L1 VMware
5.7 (L1) Host should reject MAC address changes on standard virtual switches and port groupsVMwareCIS VMware ESXi 8.0 v1.3.0 L1 VMware
5.8 (L1) Host should reject promiscuous mode requests on standard virtual switches and port groupsVMwareCIS VMware ESXi 8.0 v1.3.0 L1 VMware
5.9 (L1) Host must restrict access to a default or native VLAN on standard virtual switchesVMwareCIS VMware ESXi 8.0 v1.3.0 L1 VMware
5.10 (L1) Host must restrict the use of Virtual Guest Tagging (VGT) on standard virtual switchesVMwareCIS VMware ESXi 8.0 v1.3.0 L1 VMware
6.17 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsPalo_AltoCIS Palo Alto Firewall 10 v1.3.0 L1
18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v4.0.0 L1 NG
18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v4.0.0 L1
18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 10 EMS Gateway v3.0.0 L1
18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL
18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NG
18.6.21.2 (L2) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)WindowsCIS Windows Server 2012 R2 MS L2 v3.0.0
18.6.21.2 (L2) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2016 v4.0.0 L2 MS
18.6.21.2 (L2) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)WindowsCIS Windows Server 2012 MS L2 v3.0.0
18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v5.1.0 L1
18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v5.1.0 L1 BL
18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2025 v2.1.0 L2 MS
18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2019 v5.0.0 L2 MS
18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)WindowsCIS Microsoft Windows Server 2022 v5.1.0 L2 MS