STIGUI
V-282680CAT II — Medium severitySV-282680r1201020_rule

TOSS 5 must not have unauthorized IP tunnels configured.

Rule version TOSS-05-000206 · STIG v1 · 2026-08-20

Discussion

IP tunneling mechanisms can be used to bypass network filtering. If tunneling is required, it must be documented with the information system security officer (ISSO).

Check

Verify TOSS 5 does not have unauthorized IP tunnels configured.

Determine if the "IPsec" service is active using the following command:

$ systemctl status ipsec

ipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled) Active: inactive (dead)

If the "IPsec" service is active, check for configured IPsec connections ("conn"), using the following command:

$ grep -rni conn /etc/ipsec.conf /etc/ipsec.d/ 

Verify any returned results are documented with the ISSO.

If the IPsec tunnels are active and not approved, this is a finding.

Fix

Remove all unapproved tunnels from the system or document them with the ISSO.

Identifiers

Group ID
V-282680
Group title
SRG-OS-000480-GPOS-00227
Rule ID
SV-282680r1201020_rule
Check ID
C-87241r1201018_chk
Fix ID
F-87146r1201019_fix