SV-206692r604133_rule
V-206692
SRG-NET-000192
SRG-NET-000192-FW-000029
CAT II
10
Associate a properly configured DoS firewall filter (e.g., rules, access control lists [ACLs], screens, or policies) to outbound interfaces and security zones.
Apply a firewall filter to each outbound interface example:
set security zones security-zone untrust interfaces <OUTBOUND-INTERFACE>
set security zones security-zone trust screen untrust-screen
Obtain and review the list of outbound interfaces and zones from site personnel.
Review each of the configured outbound interfaces and zones. Verify zones that communicate outbound have been configured with the DoS firewall filter (i.e., rules, access control lists [ACLs], screens, or policies) such as IP sweeps, TCP sweeps, buffer overflows, unauthorized port scanning, SYN floods, UDP floods, and UDP sweeps.
If all outbound interfaces are not configured to block DoS attacks, this is a finding.
V-206692
False
SRG-NET-000192-FW-000029
Obtain and review the list of outbound interfaces and zones from site personnel.
Review each of the configured outbound interfaces and zones. Verify zones that communicate outbound have been configured with the DoS firewall filter (i.e., rules, access control lists [ACLs], screens, or policies) such as IP sweeps, TCP sweeps, buffer overflows, unauthorized port scanning, SYN floods, UDP floods, and UDP sweeps.
If all outbound interfaces are not configured to block DoS attacks, this is a finding.
M
2912