The router providing connectivity to the NOC must be configured to forward all in-band management traffic via an IPsec tunnel.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-207145
SRG-NET-000205-RTR-000013
SV-207145r604135_rule
Medium
Description
When the production network is managed in-band, the management network could be housed at a NOC that is located remotely at single or multiple interconnected sites. NOC interconnectivity, as well as connectivity between the NOC and the managed network, must be enabled using IPsec tunnels to provide the separation and integrity of the managed traffic.