The DataPower Gateway must not use 0.0.0.0 as a listening IP address for any service.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-65317 | SRG-NET-000364-ALG-000122 | WSDP-AG-000151 | SV-79807r1_rule | 2016-01-21 | 1 |
Description |
---|
Using 0.0.0.0 as a listening address allows all interfaces to receive traffic for the service. This creates an unnecessary exposure when services are configured to listen on this address. |
ℹ️ Check |
---|
Go to Default domain. Click Status >> Main >> Active Services >> Click Show All Domains. Review IP addresses assigned to active services. If any list 0.0.0.0, this is a finding. |
✔️ Fix |
---|
Log on to each active domain. Click Objects >> Protocol Handlers >> HTTP Front Side Handlers. Click on the name of any Handler listed that uses the IP Address of 0.0.0.0. Change the IP Address >> Click Apply. Click Objects >> Protocol Handlers >> HTTPS Front Side Handlers. Click on the name of any Handler listed that uses the IP Address of 0.0.0.0. Change the IP Address >> Click Apply >> Click Save Configuration. |