STIGUI
V-285224CAT II — Medium severitySV-285224r1244922_rule

The Ivanti Policy Secure NAC must be configured to terminate the session or redirect the endpoint to the remediation VLAN when a device requesting access fails the Host Checker policy checks.

Rule version IVPS-NC-000004 · STIG v1 · 2026-07-09

Discussion

Automated and manual procedures for remediation for critical security updates will be managed differently. Continuing to assess and remediate endpoints with risks that could endanger the network could impact network usage for all users.

Check

In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >>Host Checker.

If a Host Checker policy is not configured to terminate the session or redirect to a remediation VLAN based on the site's SSP, this is a finding.

Fix

1. In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >>Host Checker. 2. Under "Policies", click "New". 3. Type a name. 4. Click "Continue". 5. Under "Rule Settings", select "Rule type". 6. Create Host Checker rules for failed policy assessment to either terminate the session or redirect the endpoint to the remediation VLAN. 7. Click "Save Changes".

Identifiers

Group ID
V-285224
Group title
SRG-NET-000015-NAC-000060
Rule ID
SV-285224r1244922_rule
Check ID
C-89793r1244779_chk
Fix ID
F-89698r1244780_fix