SV-226306r569184_rule
V-226306
SRG-OS-000480-GPOS-00227
WN12-SO-000042
CAT III
10
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> "MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic" to "Only ISAKMP is exempt (recommended for Windows Server 2003)".
(See "Updating the Windows Security Options File" in the STIG Overview document if MSS settings are not visible in the system's policy tools.)
If the following registry value does not exist or is not configured as specified, this is a finding:
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\IPSEC\
Value Name: NoDefaultExempt
Value Type: REG_DWORD
Value: 3
V-226306
False
WN12-SO-000042
If the following registry value does not exist or is not configured as specified, this is a finding:
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\IPSEC\
Value Name: NoDefaultExempt
Value Type: REG_DWORD
Value: 3
M
4217