UCF STIG Viewer Logo

All encrypted traffic must be decrypted prior to passing through content inspection and filtering mechanisms.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000030-IDPS-NA SRG-NET-000030-IDPS-NA SRG-NET-000030-IDPS-NA_rule Medium
Description
Allowing traffic to bypass the security checkpoints such as firewalls and intrusion detection systems puts the network infrastructure and critical data at risk. Malicious traffic could enter the network undetected and attack a key IDPS or the server farm. Hence, it is imperative all encrypted traffic entering the network is decrypted prior to the content checking devices. This is a network architecture best practice and does not require a configuration setting on the IDS or IPS sensor.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43177_chk )
This requirement does not apply to IDPS.
Fix Text (F-43177_fix)
Not applicable for IDPS. No fix required.