UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The IDPS must generate a unique session identifier for each session.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000232-IDPS-000189 SRG-NET-000232-IDPS-000189 SRG-NET-000232-IDPS-000189_rule Medium
Description
Peering neighbors must have a level of trust with each other since information being shared is used to provide network services, connectivity, and optimized routing. Corrupted or erroneous information shared between the IDPS can disrupt network operations by creating non-optimized forwarding of traffic and network outages. Identifying source and destination addresses for information flows within the network allows forensic reconstruction of events when required, and increases policy compliance by attributing policy violations to specific individuals. Means to enforce this enhancement include ensuring the IDPS authenticates the source involved in sending the information. IDPS generated, unique session identifier must also be used to reduce the risk of session hi-jacking.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43342_chk )
Verify the configuration for communications to peering neighbors is configured to generate and use unique session identifiers for each communications session.

If the IDPS is not configured to generate and use unique session identifiers for each communications session, this is a finding.
Fix Text (F-43342_fix)
Configure the IDPS components to generate and use unique session identifiers for each communications session.