Check: TANS-SV-000032
Tanium 6.5 STIG:
TANS-SV-000032
(in versions v1 r3 through v1 r2)
Title
Firewall rules must be configured on the Tanium Server for Server-to-Module Server communications. (Cat II impact)
Discussion
Tanium 6.5 introduces the Tanium Module Server (formerly known as the Tanium Plugin Server) used to extend the functionality of Tanium through the use of various workbenches. The Tanium Module Server requires communication with the Tanium Server on port 17477. Port Needed: Tanium Server to Tanium Module Server over TCP port 17477. Network firewall rules: Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server. https://kb.tanium.com/Port_Configuration_v6.5
Check Content
Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server. Access the host-based firewall configuration on the Tanium Server. Validate a rule exists for the following: Port Needed: Tanium Server to Tanium Module Server over TCP port 17477. If a host-based firewall rule does not exist to allow TCP port 17477, from the Tanium Server to the Tanium Module Server, this is a finding. Consult with the network firewall administrator and validate rules exist for the following: Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server. If a network firewall rule does not exist to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.
Fix Text
Configure host-based firewall rules on the Tanium Server to allow the following required traffic: Allow TCP traffic on port 17477 to the Tanium Module Server. Configure the network firewall to allow the above traffic.
Additional Identifiers
Rule ID: SV-81595r1_rule
Vulnerability ID: V-67105
Group Title: SRG-APP-000383
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001762 |
Disable or remove organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure. |
Controls
Number | Title |
---|---|
CM-7(1) |
Periodic Review |