UCF STIG Viewer Logo

Firewall rules must be configured on the Tanium Server for Server-to-Database communications.


Overview

Finding ID Version Rule ID IA Controls Severity
V-254941 TANS-AP-000970 SV-254941r867723_rule Medium
Description
The Tanium Server can use either a SQL Server RDBMS installed locally to the same device as the Tanium Server application or a remote dedicated or shared SQL Server instance. Using a local SQL Server database typically requires no changes to network firewall rules since all communication remains on the Tanium application server device. To access database resources installed to a remote device, however, the Tanium Server service communicates over the port reserved for SQL, by default port 1433, to the database. Port Needed: Tanium Server to Remote SQL Server over TCP port 1433. Network firewall rules: Allow TCP traffic on port 1433 from the Tanium Server device to the remote device hosting the SQL Server RDBMS. https://docs.tanium.com/platform_install/platform_install/reference_network_ports.html.
STIG Date
Tanium 7.x Application on TanOS Security Technical Implementation Guide 2022-10-31

Details

Check Text ( C-58554r867721_chk )
Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Server.

1. Access the Tanium Server interactively.

2. Log on to the server with an account that has administrative privileges.

3. Access the host-based firewall configuration on the Tanium Server.

4. Validate a rule exists for the following:

4A. Port Needed: Tanium Server to Remote SQL Server over TCP port 1433.

If a host-based firewall rule does not exist to allow Tanium Server to Remote SQL Server over TCP port 1433, this is a finding.

4B. Consult with the network firewall administrator and validate rules exist for the following:

Allow traffic from Tanium Server to Remote SQL Server over TCP port 1433.

If a network firewall rule does not exist to allow traffic from Tanium Server to Remote SQL Server over TCP port 1433, this is a finding.
Fix Text (F-58498r867722_fix)
1. Configure host-based firewall rules on the Tanium Server to include the following required traffic:

1A. Allow TCP traffic on port 1433 from the Tanium Server to the Remote SQL Server.

2. Configure the network firewall to allow the above traffic.