SV-233327r611394_rule
V-233327
SRG-NET-000343-NAC-001470
FORE-NC-000190
CAT II
10
Log on to Forescout UI.
1. In the Policy tab, locate the Authentication and Authorization policy set.
2. Select a policy that identifies non-entity endpoints. Highlight the policy, then select "Edit".
3. From the Sub-Rules section, ensure that when a device is added to the MAR, the policy also applies one of the following actions:
-Access Port ACL
-Endpoint Address ACL
-WLAN Role
Verify Forescout applies dynamic ACLs that restrict the use of ports when non-entity endpoints are connected using MAC Address Repository (MAR).
If the NAC does not apply dynamic ACLs that restrict the use of ports when non-entity endpoints are connected using MAR, this is a finding.
V-233327
False
FORE-NC-000190
Verify Forescout applies dynamic ACLs that restrict the use of ports when non-entity endpoints are connected using MAC Address Repository (MAR).
If the NAC does not apply dynamic ACLs that restrict the use of ports when non-entity endpoints are connected using MAR, this is a finding.
M
5250