SV-89699r1_rule
V-75025
SRG-APP-000408-NDM-000314
MQMH-ND-001530
CAT II
10
Log on to the MQ Appliance WebGUI as a privileged user.
Go to Network icon. Select Management >> SSH Service.
Click "edit" next to the Access control list field.
Edit the SSH ACL and add authorized workstations or management network segment.
For a firewall solution, isolate the MQ SSH network interface behind the firewall and apply firewall rules to limit SSH access to only authorized management workstations or networks.
Log on to the MQ Appliance WebGUI as a privileged user.
Go to the Network icon. Select Management >> SSH Service.
Click "edit" next to the Access control list field.
View the SSH ACL and obtain the list of authorized addresses.
Ask the administrator for the list of approved addresses. If an authorized management network is in place, the SSH ACL can include a range of addresses within the authorized management network.
If a firewall is used to isolate SSH traffic, request the IP addresses of the MQ appliance and the relevant firewall ruleset.
If SSH traffic is not restricted to the list of approved addresses, this is a finding.
V-75025
False
MQMH-ND-001530
Log on to the MQ Appliance WebGUI as a privileged user.
Go to the Network icon. Select Management >> SSH Service.
Click "edit" next to the Access control list field.
View the SSH ACL and obtain the list of authorized addresses.
Ask the administrator for the list of approved addresses. If an authorized management network is in place, the SSH ACL can include a range of addresses within the authorized management network.
If a firewall is used to isolate SSH traffic, request the IP addresses of the MQ appliance and the relevant firewall ruleset.
If SSH traffic is not restricted to the list of approved addresses, this is a finding.
M
3243