Review the firewall configuration and verify that both ingress and egress traffic is being inspected for the following:
DNS Inspection: Protocol conformance, malformed packets, message length and domain name integrity. Query ID and port randomization for DNS query traffic must be enabled.
SMTP Inspection: SMTP and Extended SMTP inspection will be configured to detect spam, phishing and malformed message attacks.
FTP Inspection: FTP is not a recommended file transfer solution. Reference the Enclave STIG for conditional guidance on FTP. The firewall should inspect FTP traffic and drop connections with embedded commands, truncated commands, provide command and reply spoofing, drop invalid port negotiations, and protect FTP servers from buffer overflow.
HTTP Inspection: Inspection of HTTP traffic to servers residing in the enclave is required. Inspection of HTTP traffic from clients and servers in the enclave to servers outside the enclave is also required. HTTP inspection will be configured to filter Java applets and ActiveX objects to meet the enclave security policy. Review the security policy with the Information Assurance Officer and look for Java and ActiveX filters if the security policy requires restrictions. |