UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The firewall implementation must audit remote sessions for accessing an organizationally defined list of security functions and security-relevant information.


Overview

Finding ID Version Rule ID IA Controls Severity
V-37090 SRG-NET-000066-FW-000046 SV-48851r1_rule Low
Description
Remote access is access to organizational information systems by users (or processes acting on behalf of users) communicating through external networks (e.g., the Internet). Remote access methods include, dial-up, broadband, and wireless. Virtual private networks (VPNs), when adequately provisioned with appropriate security controls, are considered internal networks, rather than a remote access method. Unless restrictions are in place, a user connecting to the LAN via remote access can access/perform everything he/she could access/perform as those connected internally. Auditing will ensure unauthorized access to the enclave's resources and data will not go undetected. The security zone connecting to the remote access gateway must be at a lower level that the security zone where the organizationally defined list of security functions and security-relevant information resides. Access control lists can also be used to monitor (by logging all access) or restrict access to these systems.
STIG Date
Firewall Security Requirements Guide 2013-04-24

Details

Check Text ( C-45462r1_chk )
Review the access control lists or the security zones whose interface connects to a remote access gateway.
Verify access from the remote clients is monitored or restricted when making connections to specific information systems.

If the firewall implementation does not monitor and audit for unauthorized remote connections to an organizationally defined list of security functions and security-relevant information, this is a finding.
Fix Text (F-42035r1_fix)
Configure access control lists to log or restrict access to an organizationally defined list of security functions and security-relevant information.
Another acceptable method would be to configure a lower level for the security zone where the remote access gateway is connected to.