UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The firewall implementation must terminate all sessions when non-local maintenance is completed.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000178-FW-000109 SRG-NET-000178-FW-000109 SRG-NET-000178-FW-000109_rule Medium
Description
In the event the remote node has abnormally terminated or an upstream link from the managed device is down, the management session will be terminated. Thereby, freeing device resources and eliminating any possibility of an unauthorized user being orphaned to an open idle session of the managed device.
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000178-FW-000109_chk )
Review the ACLs or policy filters of the firewall. Verify sessions are terminated after an organizationally defined time period of inactivity or when session is terminated for packets identified as non-local maintenance.

If the firewall implementation does not terminate all sessions when non-local maintenance is completed, this is a finding.
Fix Text (F-SRG-NET-000178-FW-000109_fix)
Configure the firewall implementation to terminate all sessions when non-local maintenance is completed.