SV-21786r2_rule
V-19645
Deficient imp'n: UM degrades voice/data separation
VVoIP 5560
CAT II
10
Ensure the implementation of a unified mail system does not degrade the separation and traffic filtering between the voice and data security zones or VLANs.
Configure unified mail services with access to both the data and voice VLANs to NOT bridge the two environments together.
Perform a network penetration test from the data VLAN(s) to the Voice VLAN(s). Direct the scan at the unified mail connection on the data VLAN(s). Perform a similar scan in the opposite direction. This is a finding in the event the hosts on the VLAN(s) opposite the one the scanner is connected to are accessible.
V-19645
False
VVoIP 5560
Perform a network penetration test from the data VLAN(s) to the Voice VLAN(s). Direct the scan at the unified mail connection on the data VLAN(s). Perform a similar scan in the opposite direction. This is a finding in the event the hosts on the VLAN(s) opposite the one the scanner is connected to are accessible.
M
3407