UCF STIG Viewer Logo

The firewall implementation must enforce organizationally defined limitations on the embedding of data types within other data types.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000031-FW-000027 SRG-NET-000031-FW-000027 SRG-NET-000031-FW-000027_rule Medium
Description
Information flow control policies and enforcement mechanisms are commonly employed by organizations to control the flow of information between designated sources and destinations (e.g., networks, individuals, devices) within information systems and between interconnected systems. This control requires limits be set on the number of layers of encapsulation of information. With too many layers, it becomes increasingly difficult to inspect the information for malicious code. A possible enforcement mechanism for the firewall is to create a rule to monitor for and enforce organizationally defined limitations on tunneling and other encapsulation methods.
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000031-FW-000027_chk )
Verify ACLs or policy filters exist to enforce network traffic for violations of the organizationally defined limits for encapsulation layers (e.g., tunnels within tunnels).

If the firewall implementation does not enforce organizationally defined limitations on the embedding of data types within other data types, this is a finding.
Fix Text (F-SRG-NET-000031-FW-000027_fix)
Create or install a rule which filters for violations of the organizationally defined encapsulated limitations.