UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The network element must route all remote access traffic through managed access control points.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000064-IDPS-NA SRG-NET-000064-IDPS-NA SRG-NET-000064-IDPS-NA_rule Medium
Description
Remote access services enable users outside of the enclave to have access to data and services within the private network. In many instances these connections traverse the Internet. Regardless of the backbone networks used for transit between the user end-point and the remote access server (VPN appliance or firewall), remote connections must be secured and must not be given direct access to the private network. Traffic between the remote access server and the private network must be secured. Therefore, the remote access server must forward traffic destined to the private network to the firewall interface inspecting all private network ingress traffic. Routing remote access traffic through managed access control points is not a function of the IDPS.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43126_chk )
This requirement does not apply to IDPS.
Fix Text (F-43126_fix)
Not applicable for IDPS. No fix required.