SV-80885r1_rule
V-66395
SRG-NET-000192-IDPS-00140
JUSX-IP-000005
CAT II
10
To enable IDP services on outbound traffic on the device, first create a security policy for the traffic flowing in one direction, then specify the action to be taken on traffic that matches conditions specified in the policy.
[edit security policies from-zone <trusted-zone1-name> to-zone <untrusted-zone-name> policy idp-app-policy-1]
set match source-address any destination-address any application any
[edit security policies from-zone <trusted-zone-name> to-zone untrusted-zone-name> policy <idp-app-policy-name>]
set then permit application-services idp
Determine the names of the IDP policies by asking the site representative. From operational mode, enter the following command to verify outbound zones are configured with an IDP policy.
show security policies
If zones bound to the outbound interfaces, including VPN zones, are not configured with an IDP policy, this is a finding.
V-66395
False
JUSX-IP-000005
Determine the names of the IDP policies by asking the site representative. From operational mode, enter the following command to verify outbound zones are configured with an IDP policy.
show security policies
If zones bound to the outbound interfaces, including VPN zones, are not configured with an IDP policy, this is a finding.
M
3037