SV-75273r1_rule
V-60817
SRG-NET-000019-RTR-000002
AMLS-L3-000100
CAT II
10
Configure the router to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
To use an IP access list to fulfill this function, enter the following commands, substituting organizational values for the bracketed variables.
ip access-list [name]
[permit/deny] [protocol] [source address] [source port] [destination address] [destination port]
exit
interface [type] [number]
ip access-group [name] [direction]
Verify each router enforces approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
This requirement may be met through the use of IP access control lists. To verify IP access lists are configured, execute the "show ip access-lists summary" command, and check that the list is configured and is active on applicable interfaces. To verify the lists control the flow of information in accordance with organizational policy, enter the "show ip access-list [name]" command, and review the associated permit and deny statements.
If the router does not enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy, this is a finding.
V-60817
False
AMLS-L3-000100
Verify each router enforces approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.
This requirement may be met through the use of IP access control lists. To verify IP access lists are configured, execute the "show ip access-lists summary" command, and check that the list is configured and is active on applicable interfaces. To verify the lists control the flow of information in accordance with organizational policy, enter the "show ip access-list [name]" command, and review the associated permit and deny statements.
If the router does not enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy, this is a finding.
M
2823