Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000272-FW-000159 | SRG-NET-000272-FW-000159 | SRG-NET-000272-FW-000159_rule | Medium |
Description |
---|
Error messages generated by various components and services of the network devices can indicate a possible security violation or breach. The firewall implementation must detect and respond to error messages that may be a symptom of a compromise and provide notification. These error messages may be part of the network traffic on segments being monitored. Responses to these conditions include alerts or traffic dropping/blocking. If security-relevant error conditions are not identified by the firewall, intrusion attacks may remain undetected, allowing more serious damage to the network. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2012-12-10 |
Check Text ( C-SRG-NET-000272-FW-000159_chk ) |
---|
Verify ACLs or policy filters exist on the firewall to monitor the data for excessive error messages from network components. Verify ACLs or policy filters exist to identify and respond to potential security-relevant error conditions. If the system is not configured to identify and respond to potential security-relevant error conditions, this is a finding. |
Fix Text (F-SRG-NET-000272-FW-000159_fix) |
---|
Configure the system to identify and respond to potential security-relevant error conditions. |