Check: GEN000000-SOL00160
Solaris 9 X86 STIG:
GEN000000-SOL00160
(in version v1 r9)
Title
If the system is a firewall, ASET must be used on the system, and the firewall parameters must be set in /usr/aset/asetenv. (Cat II impact)
Discussion
ASET will not perform firewall tasks if it is not listed as a parameter in /usr/aset/asetenv.
Check Content
Perform the following to determine if ASET is being used. # crontab -l |grep aset A returned entry would indicate ASET is being utilized. Determine if ASET is configured to check firewall settings. # grep TASKS /usr/aset/asetenv | grep firewall If an entry is not returned, this is a finding.
Fix Text
If the system is used as a firewall and ASET is used, ensure the firewall parameter is configured in /usr/aset/asetenv.
Additional Identifiers
Rule ID: SV-4309r2_rule
Vulnerability ID: V-4309
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000032 |
The information system enforces information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows. |
CCI-000366 |
The organization implements the security configuration settings. |
CCI-001298 |
The organization reassesses the integrity of software and information by performing, on an organization-defined frequency, integrity scans of the information system. |