UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Firewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server.


Overview

Finding ID Version Rule ID IA Controls Severity
V-254942 TANS-AP-000975 SV-254942r867726_rule Medium
Description
The Tanium Module Server is used to extend the functionality of Tanium through the use of various workbenches. The Tanium Module Server requires communication with the Tanium Server on port 17477. Without a proper connection from the Tanium Server to the Tanium Module Server, access to the system capabilities could be denied. https://docs.tanium.com/platform_install/platform_install/reference_network_ports.html.
STIG Date
Tanium 7.x Application on TanOS Security Technical Implementation Guide 2022-10-31

Details

Check Text ( C-58555r867724_chk )
Consult with the Tanium System Administrator to verify which firewall is being used as a host-based firewall on the Tanium Module Server.

1. Access the Tanium Server interactively.

2. Log on to the server with an account that has administrative privileges.

3. Access the host-based firewall configuration on the Tanium Module Server.

4. Validate a rule exists for the following:

4A. Port Needed: Tanium Server to Tanium Module Server over TCP port 17477.

If a host-based firewall rule does not exist to allow TCP port 17477, from the Tanium Server to the Tanium Module Server, this is a finding.

4B. Consult with the network firewall administrator and validate rules exist for the following:

Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server.

If a network firewall rule does not exist to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.
Fix Text (F-58499r867725_fix)
1. Configure host-based firewall rules on the Tanium Module Server to include the following required traffic:

1A. Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server.

2. Configure the network firewall to allow the above traffic.