UCF STIG Viewer Logo

Remote access VoIP is not properly routed to the VoIP VLAN.


Overview

Finding ID Version Rule ID IA Controls Severity
V-19627 VVoIP 1800 (REMOTE) SV-21768r1_rule Medium
Description
In addition to complying with the STIGs and VPN requirements for remotely connected PCs, there is an additional requirement for PC soft-phone and UC applications using the VPN. Soft-phone and UC application traffic which must interact or communicate with systems and devices in the voice VLAN/protection zone must be routed to that zone while the other data and communications traffic is routed to the data zone. This is to be accomplished without degrading the separation of these two zones, or bridging them together. This can be accomplished in a number of ways depending upon the LAN and its boundary/VPN architecture.
STIG Date
VOICE and VIDEO over INTERNET PROTOCOL (VVoIP) POLICY SECURITY TECHNICAL IMPLEMENTATION GUIDE 2010-08-17

Details

Check Text ( C-23920r1_chk )
Interview the IAO to validate compliance with the following requirement:

Ensure traffic from a PC based voice (i.e., soft-phone) or unified communications application, operated in a remote access scenario and using an encrypted VPN as required, is routed to the VoIP VLAN such that the separation of the voice and data zones is not degraded while all other traffic is routed to the data zone.

Inspect network diagrams to determine if the boundary and remote access VLAN architecture properly routes VoIP traffic from the VPN to the voice VLANs while maintaining proper flow control and access between the data VLAN(s) and the voice VLAN(s). This is a finding if the boundary and remote access VLAN architecture does not properly route VoIP traffic from the VPN to the voice VLANs while maintaining proper flow control and access between the data VLAN(s) and the voice VLAN(s).
Fix Text (F-20331r1_fix)
Ensure traffic from a PC based voice (i.e., soft-phone) or unified communications application, operated in a remote access scenario and using an encrypted VPN as required, is routed to the VoIP VLAN such that the separation of the voice and data zones is not degraded while all other traffic is routed to the data zone.


Configure the enclave boundary and remote access VLAN architecture to properly route VoIP traffic from the VPN to the voice VLANs and maintain proper flow control and access between the data VLAN(s) and the voice VLAN(s).