Check: TANS-CN-000014
Tanium 6.5 STIG:
TANS-CN-000014
(in versions v1 r3 through v1 r2)
Title
Firewall rules must be configured on the Tanium Server for Console-to-Server communications. (Cat II impact)
Discussion
An HTML5/Adobe Flash based application, the Tanium Console runs from any device with a browser configured with Adobe Flash Player 11.5 or higher. For security, the TCP and SOAP communication to the Tanium Server is SSL encrypted, so the Tanium Server installer configures the server to listen for TCP and SOAP requests on port 443. If another installed application is listening on port 443, you can designate a different port for TCP and SOAP communication when installing the Tanium Server. Port Needed: To Tanium Server over TCP ports 443, 17440, and 17441 Network firewall rules: Allow TCP traffic on port 443 from any computer on the internal network to the Tanium Server device Allow TCP traffic on port 17440 from any computer on the internal network to the Tanium Server device (Patch Workbench) https://kb.tanium.com/Port_Configuration_v6.5
Check Content
Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server. Access the host-based firewall configuration on the Tanium Server. Validate a rule exists for the following: Port Needed: From only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441. If a host-based firewall rule does not exist to allow only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441, this is a finding. Consult with the network firewall administrator and validate rules exist for the following: Allow TCP traffic from only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441. If a network firewall rule does not exist to allow traffic from only designated Tanium console user clients to Tanium Server over TCP ports 443, 17440, and 17441, this is a finding.
Fix Text
Configure host-based and network firewall rules as required.
Additional Identifiers
Rule ID: SV-81511r1_rule
Vulnerability ID: V-67021
Group Title: SRG-APP-000383
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001762 |
The organization disables organization-defined functions, ports, protocols, and services within the information system deemed to be unnecessary and/or nonsecure. |
Controls
Number | Title |
---|---|
CM-7 (1) |
Periodic Review |