Check: GEN008540
Solaris 10 X86 STIG:
GEN008540
(in versions v2 r4 through v1 r17)
Title
The system's local firewall must implement a deny-all, allow-by-exception policy. (Cat II impact)
Discussion
A local firewall protects the system from exposing unnecessary or undocumented network services to the local enclave. If a system within the enclave is compromised, firewall protection on an individual system continues to protect it from attack.
Check Content
If the system is not a global zone, this vulnerability is not applicable. Check the firewall rules for a default deny rule. # ipfstat -i An example of a default deny rule is: block in log quick on ne3 from any to any. If there is no default deny rule, this is a finding.
Fix Text
Edit /etc/ipf/ipf.conf and add a default deny rule. Restart the ipfilter service. # svcadm restart network/ipfilter
Additional Identifiers
Rule ID: SV-227981r854521_rule
Vulnerability ID: V-227981
Group Title: SRG-OS-000297
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002314 |
The information system controls remote access methods. |
Controls
Number | Title |
---|---|
AC-17 (1) |
Automated Monitoring / Control |