Rule version AWTM-L2-000017 · STIG v1 · 2026-09-15
A mechanism to detect and prevent unauthorized communication flow must be configured or provided as part of the system design. If information flow is not enforced based on approved authorizations, the system may become compromised. Information flow control regulates where information is allowed to travel within a system and between interconnected systems. Security attributes may be used to manage information flow control.
Information flow enforcement mechanisms compare security attributes associated with information (data content and data structure) and source/destination objects, and respond appropriately (e.g., block, quarantine, alert administrator) when the mechanisms encounter information flows not allowed by information flow policies. For example, an information object labeled Secret would be allowed to flow to a destination object labeled Secret, but an information object labeled Top Secret would not be allowed to flow to a destination object labeled Secret. Security attributes can also include, for example, source and destination addresses employed in traffic filter firewalls. Flow enforcement using security attributes can be used, for example, to control the release of certain types of information.
This requirement also applies to Zero Trust initiatives.
Verify the Aviat WTM is configured with a Management ACL to enforce information flow control with the following steps:
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Admin >> Management ACL. 3. Verify ACL rules are configured. 4. Verify the ACL is enabled.
If no ACL rules are configured, or if the ACL is not enabled, this is a finding.
Configure the Aviat WTM with a Management ACL to enforce information flow control with the following steps:
1. Log on to the Web UI using an admin account. 2. Using the Web UI, navigate to Admin >> Management ACL. 3. Click "Add". 4. Enter a name for the ACL. 5. Under "Type", select "both". 6. Click "New TCP", set Match Port to "22", and set Action to "accept". 7. Click "New TCP", set Match Port to "443", and set Action to "accept". 8. Click "New UDP", set Match Port to "161", and set Action to "accept". 9. Click "New TCP", set Match Port to "51966", and set Action to "drop". 10. Click "New TCP", set Match Port to "51967", and set Action to "drop". 11. Click "New TCP", set Match Port to "830", and set Action to "drop". 12. Select "Enabled". 13. Click "Commit".