SV-93289r1_rule
V-78583
SRG-APP-000142
TANS-CL-000004
CAT II
10
Configure host-based and network firewall rules as required.
Note: This check is performed for the Tanium Endpoints and must be validated against the HBSS desktop firewall policy applied to the Endpoints.
Consult with the HBSS administration for assistance.
Validate a rule exists within the HBSS HIPS firewall policies for managed clients for the following:
Port Needed: Tanium Clients or Zone Clients over TCP port 17472, bi-directionally.
If a host-based firewall rule does not exist to allow TCP port 17472, bi-directionally, this is a finding.
Consult with the network firewall administrator and validate rules exist for the following:
Allow TCP traffic on port 17472 from any computer to be managed on a local area network to any other computer to be managed on the same local area network.
If a network firewall rule does not exist to allow TCP port 17472 from any managed computer to any other managed computer on the same local area network, this is a finding.
V-78583
False
TANS-CL-000004
Note: This check is performed for the Tanium Endpoints and must be validated against the HBSS desktop firewall policy applied to the Endpoints.
Consult with the HBSS administration for assistance.
Validate a rule exists within the HBSS HIPS firewall policies for managed clients for the following:
Port Needed: Tanium Clients or Zone Clients over TCP port 17472, bi-directionally.
If a host-based firewall rule does not exist to allow TCP port 17472, bi-directionally, this is a finding.
Consult with the network firewall administrator and validate rules exist for the following:
Allow TCP traffic on port 17472 from any computer to be managed on a local area network to any other computer to be managed on the same local area network.
If a network firewall rule does not exist to allow TCP port 17472 from any managed computer to any other managed computer on the same local area network, this is a finding.
M
3215