| V-284581 | CAT I · High | The Ivanti Policy Secure NAC must enforce approved access by employing preadmissions assessment filters as defined in the NAC System Security Plan (SSP). | Successful authentication must not automatically give an entity access to an asset or security boundary. The lack of authorization-based access control could result in the immediate compromise and unauthorized access to sensitive information.
Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Many NACs include the ability to create network access control policies that include identity-based policies, role-based policies, and attribute-based policies.
It is recommended the NAC have the capability to expose collected data on the assessed endpoints through an API that can be accessed externally, or the NAC solution must supply an SDK to allow customers to export data.
Admissions assessment filters should include, at a minimum, device attributes such as type, IP address, resource group, and/or mission conditions as defined in the NAC SSP. The NAC should also track the following to facilitate security investigations: when each device was last admitted/readmitted to the network; owning organization; owning organization's organizational unit; geographic location or the nearest network switch; motherboard serial number and BIOS; globally unique ID; and which unique network access compliance policies each device passed or failed during the latest network admission/readmission.
The client may be denied admission based on a returned posture token. In most NAC implementations, additional network access authorization policies can also be tied to the user's identity, but these features are out of scope for this STIG. |
| V-284582 | CAT I · High | The Ivanti Policy Secure NAC must enforce approved access by employing post-admissions assessment filters as defined in the NAC System Security Plan (SSP). | Successful authentication must not automatically give an entity access to an asset or security boundary. The lack of authorization-based access control could result in the immediate compromise and unauthorized access to sensitive information.
Configure a Host Enforcer policy in Ivanti IPS to enforce compliance checks on endpoints that connect to the network. This is typically done to ensure the endpoints meet specific security standards and are up to date with their operating systems and patches. The policy can be applied at the realm level (pre-authentication) or at the role level (post-authentication) to manage access based on compliance. Additionally, configure Host Checker policies to perform health and security checks on endpoints, including antivirus versions, OS versions, and patch checker. |
| V-284583 | CAT II · Medium | The Ivanti Policy Secure NAC must be configured to only allow users with a client-side certificate signed by Trusted Client Certificate Authorities (CAs) to sign in. | Automated policy assessments must reflect the organization's current security policy so entry control decisions will happen only where remote endpoints meet the organization's security requirements. If the remote endpoints are allowed to connect to the organization's network without passing minimum-security controls, they become a threat to the entire network.
Organizational policy must be established for what the NAC will check on the host for the agent and agentless. Use a NAC system security plan (SSP) to assess compliance with the requirement since each SSP item must be configured. |
| V-284586 | CAT II · Medium | The Ivanti Policy Secure NAC must be configured to redirect endpoints to a logically separate VLAN for remediation services for endpoints that require automated remediation. | Automated and manual procedures for remediation for critical security updates are managed differently. Continuing to assess and remediate endpoints with risks that could endanger the network could impact network usage for all users. This isolation prevents traffic from flowing with traffic from endpoints that have been fully assessed and authorized. This solution provides a mechanism to detect and prevent unauthorized communication flow must be configured or provided as part of the system design. If information flow is not enforced based on approved authorizations, the system may become compromised. Information flow control regulates where information is allowed to travel within a system and between interconnected systems. Security attributes may be used to manage information flow control.
Unauthenticated devices must not be allowed to connect to remediation services. The Ivanti IPS and client does not need to provide IP transport for evaluation and remediation. However, using this Check and Fix text works as well.
This requirement also applies to Zero Trust initiatives.
Satisfies: SRG-NET-000015-NAC-000040, SRG-NET-000323-NAC-001233 |
| V-284587 | CAT II · Medium | The Ivanti Policy Secure NAC must be configured to apply dynamic ACLs that restrict the use of resources when nonentity endpoints are connected using MAC Authentication Bypass (MAB). | MAB can be defeated by spoofing the MAC address of a valid device. MAB enables port-based access control using the MAC address of the endpoint. A MAB-enabled port can be dynamically enabled or disabled based on the MAC address of the device that connects to it.
NPE devices that support PKI or an allowed authentication type must use PKI. MAB may be used for NPE that cannot support an approved device authentication. Nonentity endpoints include IoT devices, VoIP phones, and printers.
To support MAC authentication, add a MAC authentication server to Ivanti Policy Secure. Direct configuration of authenticators on the Ivanti Policy server, including MAC addresses, is not permitted; thus, NPE MACs must be associated with a MAC authentication server with an LDAP server. |
| V-284588 | CAT II · Medium | The Ivanti Policy Secure NAC must configure maximum number of sessions per user for all user realms. | Denial-of-service (DoS) events may occur due to a variety of internal and external causes, such as an adversarial attack or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of DoS events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of DoS attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to DoS events. |
| V-285223 | CAT II · Medium | The Ivanti Policy Secure NAC must be configured to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used. | Connections that bypass established security controls should only be used in cases of administrative need. These procedures and use cases must be approved by the information system security manager (ISSM). |
| V-285224 | CAT II · Medium | The Ivanti Policy Secure NAC must be configured to terminate the session or redirect the endpoint to the remediation VLAN when a device requesting access fails the Host Checker policy checks. | Automated and manual procedures for remediation for critical security updates will be managed differently. Continuing to assess and remediate endpoints with risks that could endanger the network could impact network usage for all users. |