Check: FORE-NC-000290
Forescout Network Access Control STIG:
FORE-NC-000290
(in versions v1 r4 through v1 r3)
Title
Communications between Forescout endpoint agent and the switch must transmit access authorization information via a protected path using a cryptographic mechanism. This is required for compliance with C2C Step 1. (Cat II impact)
Discussion
Forescout solution assesses the compliance posture of each client and returns an access decision based on configured security policy. The communications associated with this traffic must be protected from alteration and spoofing attacks so unauthorized devices do not gain access to the network.
Check Content
If DoD is not at C2C Step 1 or higher, this is not a finding. Verify both ends are configured for secure communications between the NAC and NAC agent. If communication between the NAC and NAC agent does not use an encrypted method for protecting posture information transmitted between the devices, this is a finding.
Fix Text
Log on to the Forescout UI. 1. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 2. In the Client-Server Connection, check the Minimum Supported TLS Version is set to TLS version 1.2.
Additional Identifiers
Rule ID: SV-233334r856516_rule
Vulnerability ID: V-233334
Group Title: SRG-NET-000320-NAC-001200
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002353 |
The information system transmits organization-defined access authorization information using organization-defined security safeguards to organization-defined information systems which enforce access control decisions. |
Controls
Number | Title |
---|---|
AC-24 (1) |
Transmit Access Authorization Information |