STIGQter STIGQter: STIG Summary: Firewall Security Requirements Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

The firewall must be configured to inspect all inbound and outbound IPv6 traffic for unknown or out-of-order extension headers.

DISA Rule

SV-223012r604133_rule

Vulnerability Number

V-223012

Group Title

SRG-NET-000364

Rule Version

SRG-NET-000364-FW-000041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the firewall to inspect all inbound and outbound traffic at the application layer.

Check Contents

Review the firewall configuration to verify that IPv6 inspection is being performed on all interfaces.
If the firewall is not configujred to inspect all inbound and outbound IPv6 traffic for unknown or out-of-order extension headers, this is a finding.

Vulnerability Number

V-223012

Documentable

False

Rule Version

SRG-NET-000364-FW-000041

Severity Override Guidance

Review the firewall configuration to verify that IPv6 inspection is being performed on all interfaces.
If the firewall is not configujred to inspect all inbound and outbound IPv6 traffic for unknown or out-of-order extension headers, this is a finding.

Check Content Reference

M

Target Key

2912

Comments