Check: SRG-NET-000512-VVEP-00001
Voice Video Endpoint SRG:
SRG-NET-000512-VVEP-00001
(in versions v2 r2 through v1 r4)
Title
The hardware Voice Video Endpoint must integrate into the implemented 802.1x network access control system. (Cat II impact)
Discussion
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters. Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
Check Content
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint integrates into the implemented 802.1x network access control system. If the hardware Voice Video Endpoint does not integrate into the implemented 802.1x network access control system, this is a finding.
Fix Text
Configure the hardware Voice Video Endpoint to integrate into the implemented 802.1x network access control system.
Additional Identifiers
Rule ID: SV-206786r604140_rule
Vulnerability ID: V-206786
Group Title: SRG-NET-000512
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |