| If DoD is not at C2C Step 2 or higher, this is not a finding. |
1. Select Tools >> Options >> Appliance >> IP Assignment.
2. Select Segment >> IP Addresses.
3. Verify the IP address for the DMZ subnet is not present.
If Forescout is not configured so the devices and servers in the Forescout solution (e.g., NAC, assessment server, policy decision point) do not communicate with other network devices in the DMZ or subnet except as needed to perform a remote access client assessment or to identify itself, this is a finding.