UCF STIG Viewer Logo

All encrypted traffic must be decrypted prior to passing through content inspection and filtering mechanisms.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34500 SRG-NET-000030-IDPS-NA SV-45322r1_rule Medium
Description
Allowing traffic to bypass the security checkpoints, such as firewalls and intrusion detection systems, puts the network infrastructure and critical data at risk. Malicious traffic could enter the network undetected and attack a key IDPS or the server farm. Hence, it is imperative all encrypted traffic entering the network is decrypted prior to the content checking devices. Encryption and decryption of traffic for filtering is not a function of IDPS. This is a network architecture best practice and does not require a configuration setting in the IDPS components.
STIG Date
Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide 2012-11-19

Details

Check Text ( C-42670r1_chk )
This requirement is NA for IDPS. No fix required.
Fix Text (F-38718r1_fix)
This requirement is NA for IDPS. No fix required.