Check: GEN000000-SOL00160
Solaris 10 X86 STIG:
GEN000000-SOL00160
(in versions v2 r4 through v1 r17)
Title
If the system is a firewall, ASET must be used on the system, and the firewall parameters must be set in /usr/aset/asetenv. (Cat II impact)
Discussion
ASET will not perform firewall tasks if it is not listed as a parameter in /usr/aset/asetenv.
Check Content
Perform the following to determine if ASET is being used. # crontab -l |grep aset A returned entry would indicate ASET is being utilized. Determine if ASET is configured to check firewall settings. # grep TASKS /usr/aset/asetenv | grep firewall If an entry is not returned, this is a finding.
Fix Text
If the system is used as a firewall and ASET is used, ensure the firewall parameter is configured in /usr/aset/asetenv.
Additional Identifiers
Rule ID: SV-227539r603266_rule
Vulnerability ID: V-227539
Group Title: SRG-OS-000016
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000032 |
Enforce information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows. |
CCI-000366 |
Implement the security configuration settings. |