SV-19076r4_rule
V-17822
The management interface does not have an ACL.
NET0992
CAT II
10
If the management interface is a routed interface, it must be configured with both an ingress and egress ACL. The ingress ACL should block any transit traffic, while the egress ACL should block any traffic that was not originated by the managed network device.
Step 1: Verify the managed interface has an inbound and outbound ACL or filter.
Step 2: Verify the ingress ACL blocks all transit traffic--that is, any traffic not destined to the router itself. In addition, traffic accessing the managed elements should be originated at the NOC.
Step 3: Verify the egress ACL blocks any traffic not originated by the managed element.
If management interface does not have an ingress and egress filter configured and applied, this is a finding.
V-17822
False
NET0992
Step 1: Verify the managed interface has an inbound and outbound ACL or filter.
Step 2: Verify the ingress ACL blocks all transit traffic--that is, any traffic not destined to the router itself. In addition, traffic accessing the managed elements should be originated at the NOC.
Step 3: Verify the egress ACL blocks any traffic not originated by the managed element.
If management interface does not have an ingress and egress filter configured and applied, this is a finding.
M
Information Assurance Officer
1538