UCF STIG Viewer Logo

The firewall implementation must audit remote sessions for accessing an organizationally defined list of security functions and security-relevant information.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000066-FW-000048 SRG-NET-000066-FW-000048 SRG-NET-000066-FW-000048_rule Low
Description
Remote access services enable users outside of the enclave (external interface) to have access to data and services within the private network. In many instances these connections traverse the Internet. Monitoring of remote access sessions allows organizations to audit user activities and to ensure compliance with the remote access policy. Unless restrictions are put in place, a user connecting to the LAN via remote access can access/perform everything he/she could access/perform as those connected internally. Auditing will ensure unauthorized access to the enclave's resources and data will not go undetected. The security zone connecting to the remote access gateway must be at a lower level that the security zone where the organizationally defined list of security functions and security-relevant information resides. Access control lists can also be used to monitor (by logging all access) or restrict access to these systems.
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000066-FW-000048_chk )
Review the access control lists or the security zones whose interface connects to a remote access gateway and verify that access from the remote clients is monitored or restricted when making connections to specific information systems.

If the firewall implementation does not monitor and audit for unauthorized remote connections to an organizationally defined list of security functions and security-relevant information, this is a finding.
Fix Text (F-SRG-NET-000066-FW-000048_fix)
Configure access control lists to log or restrict access to an organizationally defined list of security functions and security-relevant information.
Another acceptable method would be to configure a lower level for the security zone where the remote access gateway is connected to.