SV-8801r1_rule
V-8306
Deficient design: EI “PC port” switch VLAN suppt
VVoIP 5700 (LAN)
CAT II
10
Ensure a VVoIP or VTC hardware endpoint possessing a “PC Port” contains an Ethernet switch such that VLAN separation can be maintained and that it does not contain an Ethernet hub OR ensure the “PC Port” is physically disabled.
In the event the endpoints do not support VLAN separation or cannot/do not tag their traffic with the appropriate VLAN ID (802.1Q tag), Physically inspect a random sampling of VVoIP or VTC endpoints to determine if the PC port is physically disabled or blocked from use. Of not, plug a PC into the PC port and determine if it has access to the LAN or the configuration of or communications traffic from the phone. This is a finding if this condition is true and the PC port is not physically disabled or blocked or the PC has access to the LAN or the phone.
V-8306
False
VVoIP 5700 (LAN)
VVoIP 5700
In the event the endpoints do not support VLAN separation or cannot/do not tag their traffic with the appropriate VLAN ID (802.1Q tag), Physically inspect a random sampling of VVoIP or VTC endpoints to determine if the PC port is physically disabled or blocked from use. Of not, plug a PC into the PC port and determine if it has access to the LAN or the configuration of or communications traffic from the phone. This is a finding if this condition is true and the PC port is not physically disabled or blocked or the PC has access to the LAN or the phone.
M
Denial of Service and/or unauthorized access to network or voice system resources or services and the information they contain. Loss of confidentiality. Degradation of the data and VoIP network segregation and associated problems.
Physically disable or incapacitate the PC port so that it cannot be activated and used.
Information Assurance Officer
594