SV-223228r513373_rule
V-223228
SRG-APP-000412-NDM-000331
JUSX-DM-000152
CAT II
10
Remove host-inbound-traffic systems-services option from zones not authorized for management traffic.
Remove unauthorized protocols (e.g., HTTP, HTTPS) from management zones that are configured to allow host-inbound-traffic system-services.
Verify only those zones where management functionality is allowed have host-inbound-traffic system-services configured and that protocols such as HTTP and HTTPS are not assigned to these zones.
[edit]
show security zones functional-zone management
If zones configured for host-inbound-traffic system-services have protocols other than SSH configured, this is a finding.
V-223228
False
JUSX-DM-000152
Verify only those zones where management functionality is allowed have host-inbound-traffic system-services configured and that protocols such as HTTP and HTTPS are not assigned to these zones.
[edit]
show security zones functional-zone management
If zones configured for host-inbound-traffic system-services have protocols other than SSH configured, this is a finding.
M
4098