Firewall rules must be configured on the Tanium module server to allow Server-to-Module Server communications from the Tanium Server.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-254942SRG-APP-000383TANS-AP-000975SV-254942r1067730_rule2025-02-112
Description
The Tanium Module Server is used to extend the functionality of Tanium through the use of various workbenches. The Tanium Module Server requires communication with the Tanium Server on port 17477. Without a proper connection from the Tanium Server to the Tanium Module Server, access to the system capabilities could be denied. https://docs.tanium.com/platform_install/platform_install/reference_network_ports.html.
ℹ️ Check
Consult with the network firewall administrator and validate rules exist for the following: - Allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server. If a network firewall rule does not exist to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server, this is a finding.
✔️ Fix
Configure the network firewall to allow TCP traffic on port 17477 from the Tanium Server to the Tanium Module Server.