STIGUI
V-284443CAT II — Medium severitySV-284443r1244819_rule

The Ivanti Policy Secure must be configured to use IP segments separate from the production VLAN when NAC policy assessment and remediation are used.

Rule version IVPS-AA-000027 · STIG v1 · 2026-07-09

Discussion

When policy assessment and remediation have been implemented and the advanced AAA server dynamic VLAN is misconfigured, logical separation of the production VLAN may not be ensured.

Nontrusted resources are not authenticated in a NAC solution and only implement the authentication component of NAC. Nontrusted resources could become resources that have been authenticated but have not had a successful policy assessment when the automated policy assessment component has been implemented.

Check

1. In the Web UI, navigate to Network >> Internal >> Settings. 2. Verify the IP address for the "Internal Interface" is set to an IP address of a separate network segment rather than the production network.

If Ivanti Policy Secure is not configured for network separation from the trusted network segments, this is a finding.

Fix

1. In the Web UI, navigate to Network >> Internal >> Settings. 2. Set the IP address for the "Internal Interface" to the address of a network segment separate from the production network (this network may have services such as AD, web servers, etc.).

Identifiers

Group ID
V-284443
Group title
SRG-APP-000516-AAA-000650
Rule ID
SV-284443r1244819_rule
Check ID
C-89008r1244541_chk
Fix ID
F-88913r1244542_fix