Forescout Network Access Control Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000010
- Vuln IDs
-
- V-233309
- Rule IDs
-
- SV-233309r611394_rule
Checks: C-36504r605630_chk
Verify Forescout has been configured to include assessment filters for device attributes such as type, IP address, resource group, mission conditions, and other criteria as defined in the NAC SSP. If the NAC does not employ admissions assessment filters which include, at a minimum, device attributes such as type, IP address, resource group, mission conditions, and other criteria as defined in the NAC SSP, this is a finding.
Fix: F-36469r605631_fix
Configure Forescout with device attribute policies that include type, IP address, resource group, mission conditions, and other criteria as defined in the NAC SSP. 1. Log on to Forescout UI. 2. From the Policy tab, select the top most policy. 3. Select Add >> Classification >> Primary Classification, and then click "Next". 4. Give the policy a name, then click "Next". 5. Select the IP Address Range the policy will apply to, click "Ok", and then click "Next". 6. Select "Finish, then click "Apply".
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000020
- Vuln IDs
-
- V-233310
- Rule IDs
-
- SV-233310r611394_rule
Checks: C-36505r605633_chk
Determine if Forescout is configured to confirm endpoint policy assessment after the endpoint attempting access has been identified using an approved identification method. 1. Log on to the Forescout Administrator UI. 2. From the Home screen select the "Policy" tab. 3. Verify that policies exist that assess compliance in accordance with the SSP. 4. Examples include, but are not limited to: - Verification that anti-virus software is authorized, running, and virus signatures are up to date. - Host-based firewall installed and configured according to the organization's security policy. - Host IDS/IPS is installed, operational, and up to date. - Uses the result of malware, anti-virus, and IDS scans and status as part of the assessment decision process. - Required BIOS, operating system, browser, and office application patch levels. - Performs an assessment of the list of running services. - Test for the presence of DoD-required software. - Test for presence of peer-to-peer software (not allowed). If Forescout does not have existing compliance assessment policies, this is a finding.
Fix: F-36470r605634_fix
Configure Forescout to identify the endpoint. 1. From the console on the Enterprise Manager console, select the Policy tab. 2. In accordance with the SSP, ensure that the endpoint compliance assessment policies have been configured and are functioning properly.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000030
- Vuln IDs
-
- V-233311
- Rule IDs
-
- SV-233311r616544_rule
Checks: C-36506r605636_chk
If automated remediation is not required by the SSP, this is not a finding. Verify Forescout is configured to redirect endpoints requiring automated remediation to a separated VLAN that is isolated from trusted traffic. 1. From the Policy tab, select the top most policy. 2. Verify at least one endpoint policy exists that redirects failed endpoints to a VLAN that is separate from the trusted network. If Forescout does not have one or more policies that redirect endpoints that require automated remediation to a VLAN that is isolated and logically separated, this is a finding.
Fix: F-36471r616543_fix
Configure Forescout to identify the endpoint. 1. From the Policy tab, select the top most policy. 2. Select Add >> Classification >> Primary Classification, and then click Next. 3. Give the policy a name, then click Next. 4. Select the IP Address Range the policy will apply to, click "OK," and then click "Next". 5. Select "Finish", and then click "Apply". This collects a series of attributes for each endpoint that can then be used in a policy as the unique identifier. However, by default the IP address is used, for example in the log records.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000040
- Vuln IDs
-
- V-233312
- Rule IDs
-
- SV-233312r615851_rule
Checks: C-36507r615850_chk
Verify Forescout is configured to filter the policy assessment devices based on risk and are remediated accordingly based on local SSP. Verify filters for the policy assessment devices are set to take remediation actions. 1. In the Forescout UI, go to the Policy Tab >> Compliance Policies. 2. Verify the action within the Compliance Policies is configured with one of the following actions: - Terminate the connection and place the device on a "blacklist" to prevent future connection attempts until action is taken to remove the device from the blacklist. - Redirect traffic from the remote endpoint to the automated remediation subnet for connection to the remediation server. - Allow the device access to limited network services such as public web servers in the protected DMZ (must be approved by the AO). - Allow the device and user full entry into the protected networks but flag it for future remediation. With this option, an automated reminder should be used to inform the user of the remediation status. If Forescout does not communicate with the remote access gateway to implement a policy to either terminate the session or redirect the session for endpoint remediation, this is a finding.
Fix: F-36472r605640_fix
Configure Forescout policy to take remediation actions on endpoints with risk. 1. In the Forescout UI, go to the Policy Tab >> Compliance Policies. 2. Select a policy, then click Edit. 3. Configure the Compliance Policies to include any of the following actions: - Terminate the connection and place the device on a "blacklist" to prevent future connection attempts until action is taken to remove the device from the blacklist. - Redirect traffic from the remote endpoint to the automated remediation subnet for connection to the remediation server. - Allow the device access to limited network services such as public web servers in the protected DMZ (must be approved by the AO). - Allow the device and user full entry into the protected networks but flag it for future remediation. With this option, an automated reminder must be used to inform the user of the remediation status.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- FORE-NC-000050
- Vuln IDs
-
- V-233313
- Rule IDs
-
- SV-233313r615864_rule
Checks: C-36508r615863_chk
Check Forescout policy to ensure that exempt devices that are in need of remediation prompt the user to accept the remediation process, prior to conducting. 1. Log on to the Forescout UI. 2. Select the "Policy" tab. 3. Review the compliance policy identified by the site representation as the remediation policy, then click "Edit". 4. In the Sub-Rules section, select a policy and click "Edit". 5. From the Actions section, verify that the policy is configured to notify the user, prior to remediation, that user interaction is required. If Forescout is not configured to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used, this is a finding.
Fix: F-36473r605643_fix
Log on to the Forescout UI. 1. Select the "Policy" tab. 2. Select a compliance policy, then click "Edit". 3. In the Sub-Rules section, select a policy and click "Edit". 4. From the Actions section, click Add >> Notify >> and select a notification method.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000060
- Vuln IDs
-
- V-233314
- Rule IDs
-
- SV-233314r615869_rule
Checks: C-36509r605645_chk
If traffic is not allowed to bypass the NAC policy, this is not a finding. Verify a policy exists that uses the exemption group configured so that all client machines are assessed by Forescout with exceptions that are allowed to bypass Forescout based on account or account type, as approved by the ISSM and documented in the SSP. 1. In the filters pane under Groups, right-click the group editor. Pick the group indicated as compliance by the site representative. 2. Click "Scope" and review the Exemptions Group. If remediation is being performed, ensure the ISSM has approved any bypass procedure configured in the NAC. If Forescout is not configured to approve all instances where traffic is allowed to bypass the NAC as approved by the ISSM, this is a finding.
Fix: F-36474r615852_fix
Forescout allows exception by User Names or individual MAC or IP addresses. DoD requires the best practice of using a group and applying policy to the group. Create a group based on the exemptions in the SSP. 1. In the filters pane under Groups, right-click the group editor. Pick or create an exemption group. 2. Add a name, then add the scope based on IP range or Subnet, or add based on MAC Address. 3. Click "OK", and then "OK" again. Click "Yes" for "Are you sure?". Create a policy that uses the exemption group. 1. In the Views pane, click "Authentication & Authorization". 2. Select an existing policy and Edit the Scope to add the Exemptions Group. 3. In Exceptions type, select "Group". 4. In the Policy screen, select the exceptions group created in the prior step, click "OK" several times, and then click "Apply".
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000070
- Vuln IDs
-
- V-233315
- Rule IDs
-
- SV-233315r611394_rule
Checks: C-36510r605648_chk
Check Forescout policy and ensure it is configured to prohibit the use of DHCP to separate authenticated and non-authenticated network access requests. If the NAC does not prohibit the use of DHCP to separate authenticated and non-authenticated network access requests, this is a finding.
Fix: F-36475r605649_fix
Log on to the Forescout UI. 1. Locate the Authentication & Authorization policy. 2. Ensure all traffic passing through the NAC is properly labeled and that all authenticated and non-authenticated traffic goes through the NAC.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- FORE-NC-000080
- Vuln IDs
-
- V-233316
- Rule IDs
-
- SV-233316r611394_rule
Checks: C-36511r605651_chk
Verify Forescout performs device authentication before policy assessment is performed. If device authentication is not completed prior to the NAC check, this is a finding.
Fix: F-36476r605652_fix
Log on to the Forescout UI. 1. Locate the Authentication & Authorization policy. 2. Ensure the Authentication & Authorization policy happens prior to any NAC check.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- FORE-NC-000090
- Vuln IDs
-
- V-233317
- Rule IDs
-
- SV-233317r611394_rule
Checks: C-36512r605654_chk
Verify Forescout sends user and/or admin notification of remediation requirements, whether manual or automated. If the NAC does not flag for future manual or automated remediation, devices failing policy assessment that are not automatically remediated either before or during the remote access session, this a finding.
Fix: F-36477r605655_fix
Log on to the Forescout UI. 1. Within the Policy tab, locate the Compliance policies. 2. Within the policy Sub-Rule, ensure all policies that indicate remediation have been configured to notify the user and/or network administrator of required action.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- FORE-NC-000100
- Vuln IDs
-
- V-233318
- Rule IDs
-
- SV-233318r611394_rule
Checks: C-36513r605657_chk
Check Forescout policy to ensure that any device with a critical security issue is checked through a security policy and an action is taken to either blacklist it or terminate communication with other network devices. If the NAC does not immediately place the device on the blacklist and terminate the connection when critical security issues are found that put the network at immediate risk, this a finding.
Fix: F-36478r605658_fix
Login to the Forescout UI. 1. From the Policy tab, identify a Compliance policy. 2. Within the Compliance policy, under Sub-Rule for a device with critical security issues, ensure that an action that Adds Device to Blacklist and/or Disables Device, is enabled.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- FORE-NC-000110
- Vuln IDs
-
- V-233319
- Rule IDs
-
- SV-233319r611394_rule
Checks: C-36514r605660_chk
1. Select Tools >> Options >> Appliance >> IP Assignment. 2. Select Segment >> IP Addresses. 3. Verify the IP address for the DMZ subnet is not present. If Forescout is not configured so the devices and servers in the Forescout solution (e.g., NAC, assessment server, policy decision point) do not communicate with other network devices in the DMZ or subnet except as needed to perform a remote access client assessment or to identify itself, this is a finding.
Fix: F-36479r605661_fix
Configure Forescout to prevent communication with other hosts in the DMZ that do not perform security policy assessment or remediation services. 1. Log on to the Forescout UI. 2. Select Tools >> Options >> Appliance >> IP Assignment. 3. Select Segment >> IP Addresses. Find the IP address for the DMZ subnet and delete it.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-002178
- Version
- FORE-NC-000120
- Vuln IDs
-
- V-233320
- Rule IDs
-
- SV-233320r611394_rule
Checks: C-36515r605663_chk
Verify Forescout admission policy has been configured to revoke access to endpoints that have not met or are removed from the authorized group. If Forescout is not configured with an admissions policy that enforces the revocation of endpoint access authorizations based on when devices are removed from an authorization group, this is a finding.
Fix: F-36480r605664_fix
Log on to the Forescout UI. From the Policy tab, check that the authorization policy has a Block Action enabled on any devices that have not met or are removed from the authorized group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-002179
- Version
- FORE-NC-000130
- Vuln IDs
-
- V-233321
- Rule IDs
-
- SV-233321r611394_rule
Checks: C-36516r605666_chk
Verify Forescout admission policy has been configured to revoke access to endpoints that have not met or are removed from the authorized group. If Forescout is not configured with an admissions policy that enforces the revocation of endpoint access authorizations based on when devices are removed from an authorization group, this is a finding.
Fix: F-36481r605667_fix
Log on to the Forescout UI. From the Policy tab, check that the authorization policy has a Block Action enabled on any devices that have not met or are removed from the authorized group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-002179
- Version
- FORE-NC-000140
- Vuln IDs
-
- V-233322
- Rule IDs
-
- SV-233322r611394_rule
Checks: C-36517r605669_chk
Verify Forescout has been configured to redirect filtered devices to a limited access network to include a remediation network or limited access network. If a policy does not exist that redirects the failed device to an authorized network for remediation or limited access, this is not a finding. If the NAC does not deny or restrict access for endpoints that fail critical endpoint security checks, this is a finding.
Fix: F-36482r605670_fix
Log on to the Forescout UI. From the Policy tab, check any Pre-Connect policies to ensure devices that fail the baseline security configuration requirements are set to either restrict access to production network, are granted access to only remediation network, or are granted to a limited access network.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001844
- Version
- FORE-NC-000150
- Vuln IDs
-
- V-233323
- Rule IDs
-
- SV-233323r611394_rule
Checks: C-36518r605672_chk
1. Go to Tools >> Options >> Syslog. 2. Verify a central log server's IP address is configured. If Forescout does not configured to log records onto a centralized events server, this is a finding.
Fix: F-36483r605673_fix
Configure Syslog server with TCP, as well as configure Syslog to alert if the communication between the Syslog server and the Forescout appliance loses connectivity. 1. Go to Tools >> Options >> Syslog. 2. Click Add/Edit. 3. Configure the Syslog: - Syslog Server IP address - Server Port - Server Protocol set to TCP - Check the Use TLS setting - Configure the Identity, Facility, and Severity. 4. Click "Ok". 5. Click "Apply". Note: A secondary syslog server is required to fully meet this requirement (covered in NDM STIG). Use the same instructions to configure a second syslog.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- FORE-NC-000160
- Vuln IDs
-
- V-233324
- Rule IDs
-
- SV-233324r611394_rule
Checks: C-36519r605675_chk
1. Go to Tools >> Options >> Syslog. 2. Verify a syslog server's IP address is configured. If each Forescout device does not offload log records to a separate device, this is a finding.
Fix: F-36484r605676_fix
Configure Syslog server with TCP, as well as configure Syslog to alert if the communication between the Syslog server and the Forescout appliance loses connectivity. 1. Go to Tools >> Options >> Syslog. 2. Click Add/Edit. 3. Configure the Syslog: - Syslog Server IP address - Server Port - Server Protocol set to TCP - Check the Use TLS setting - Configure the Identity, Facility, and Severity. 4. Click "Ok". 5. Click "Apply".
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001858
- Version
- FORE-NC-000170
- Vuln IDs
-
- V-233325
- Rule IDs
-
- SV-233325r615865_rule
Checks: C-36520r605678_chk
Verify Forescout sends an alert to the proper security personnel when an audit process failure occurs. 1. Log on to the Forescout UI. 2. Locate the audit process policies as identified by the site representative. 3. Verify a policy for "audit failure" exists. 4. Verify this policy includes notification of security personnel. If Forescout does not send an alert when an audit processing failure occurs, this is a finding.
Fix: F-36485r605679_fix
Log on to the Forescout UI. 1. Locate the audit process policies as identified by the site representative. 2. Configure a policy for audit failure to include the notification of security personnel. This could also include sending a balloon message, notification, or email.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- FORE-NC-000180
- Vuln IDs
-
- V-233326
- Rule IDs
-
- SV-233326r615862_rule
Checks: C-36521r605681_chk
1. Log on to the Forescout UI. 2. Select Tools >> Option >> Appliance >> IP Assignment. 3. Verify all IP addresses associated with the SSP are labeled within the IP Assignments list. If Forescout does not authenticate all endpoints prior to establishing a connection and proceeding with posture assessment, this is a finding.
Fix: F-36486r615861_fix
1. Log on to the Forescout UI. 2. Select Tools >> Option >> Appliance >> IP Assignment. 3. Configure IP addresses associated with the SSP and label within the IP Assignments list, and then select "Apply".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- FORE-NC-000190
- Vuln IDs
-
- V-233327
- Rule IDs
-
- SV-233327r611394_rule
Checks: C-36522r605684_chk
Verify Forescout applies dynamic ACLs that restrict the use of ports when non-entity endpoints are connected using MAC Address Repository (MAR). If the NAC does not apply dynamic ACLs that restrict the use of ports when non-entity endpoints are connected using MAR, this is a finding.
Fix: F-36487r605685_fix
Log on to Forescout UI. 1. In the Policy tab, locate the Authentication and Authorization policy set. 2. Select a policy that identifies non-entity endpoints. Highlight the policy, then select "Edit". 3. From the Sub-Rules section, ensure that when a device is added to the MAR, the policy also applies one of the following actions: -Access Port ACL -Endpoint Address ACL -WLAN Role
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- FORE-NC-000210
- Vuln IDs
-
- V-233328
- Rule IDs
-
- SV-233328r615856_rule
Checks: C-36523r615854_chk
Verify Forescout is configured to reveal error messages only to the security personnel that need to know about the application that had the error. 1. Log on to the Forescout UI. 2. Within the highlighted policy, under the Actions section, select a configured action to view. 3. Find the Notify section and verify that only authorized individuals (IAW the SSP) are configured for the following: - HTTP Notification - Send Email - Send Notification If Forescout error messages can be viewed by unauthorized users other than the security personnel that have a need to know, this is a finding.
Fix: F-36488r615855_fix
1. Log on to the Forescout UI. 2. Within the highlighted policy, under the Actions section, select "Add" or "Edit". 3. Find the Notify section and select from any one of the below options for notifying authorized (IAW SSP) personnel: - HTTP Notification - Send Email - Send Notification
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- FORE-NC-000230
- Vuln IDs
-
- V-233329
- Rule IDs
-
- SV-233329r615867_rule
Checks: C-36524r615866_chk
1. Go to Tools >> Options >> Syslog. 2. Verify the Server Protocol is set to TCP. 3. Verify "Use TLS" setting is set. 4. Verify the "Identity, Facility, and Severity" setting is configured. If Forescout does not use TCP for the syslog protocol, this is a finding.
Fix: F-36489r605691_fix
Configure Syslog server with TCP, as well as configure Syslog to alert if the communication between the Syslog server and the Forescout appliance loses connectivity. 1. Go to Tools >> Options >> Syslog. 2. Click Add/Edit. 3. Configure the Syslog: - Syslog Server IP address - Server Port - Server Protocol set to TCP - Check the Use TLS setting - Configure the Identity, Facility, and Severity. 4. Click "OK". 5. Click "Apply".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- FORE-NC-000240
- Vuln IDs
-
- V-233330
- Rule IDs
-
- SV-233330r616542_rule
Checks: C-36525r616541_chk
Review the switch configuration to verify each access port is configured for a single registered MAC address. 1. Log on to the Forescout UI. 2. Go to Tools >> Options >> Switch >> Permissions >> Advanced. 3. Verify the "Maximum connected endpoints per port" is set to "1". If Forescout switch is not configured to permit a maximum of one registered MAC address per access port, this is a finding.
Fix: F-36490r605694_fix
Forescout has the ability to configure the amount of Maximum connected endpoints per port. 1. Log on to the Forescout UI. 2. Go to Tools >> Options >> Switch >> Permissions >> Advanced. 3. Set the Maximum connected endpoints per port to one.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- FORE-NC-000260
- Vuln IDs
-
- V-233331
- Rule IDs
-
- SV-233331r611394_rule
Checks: C-36526r605696_chk
Verify Forescout is configured to a list of DoD-approved certificate types and CAs. Verify the TLS session is configured to automatically terminate any session if the client does not have a suitable certificate. For TLS connections, if Forescout is not configured to automatically terminate the session when the client does not have a suitable certificate, this is a finding.
Fix: F-36491r605697_fix
Log on to the Forescout UI. 1. Select Tools >> Options >> Certificates. 2. Check that in the Ongoing TLS Sessions section, view the Re-verify TLS Sessions. 3. Change the Re-verify TLS Sessions to Every 1 Day or in accordance with the site's SSP, then click "Apply". 4. Next select the HPS Inspection Engine >> SecureConnector. 5. In the Client-Server Connection, ensure the Minimum Supported TLS Version is set to TLS version 1.2.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- FORE-NC-000270
- Vuln IDs
-
- V-233332
- Rule IDs
-
- SV-233332r611394_rule
Checks: C-36527r605699_chk
Verify Forescout is configured to a list of DoD-approved certificate types and CAs. Verify the TLS session is configured to automatically terminate any session if the client does not have a suitable certificate. For TLS connections, if Forescout is not configured to use TLS 1.2 at a minimum, this is a finding.
Fix: F-36492r605700_fix
Log on to the Forescout UI. 1. Select Tools >> Options >> Certificates. 2. Check that in the Ongoing TLS Sessions section, view the Re-verify TLS Sessions. 3. Change the Re-verify TLS Sessions to Every 1 Day or in accordance with the site's SSP, then click "Apply". 4. Next select the HPS Inspection Engine >> SecureConnector. 5. In the Client-Server Connection, ensure the Minimum Supported TLS Version is set to TLS version 1.2.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- FORE-NC-000280
- Vuln IDs
-
- V-233333
- Rule IDs
-
- SV-233333r611394_rule
Checks: C-36528r605702_chk
If the NAC does not store device keys, this is not applicable. Verify the NAC is configured to use FIPS-mode or a key management process that is protected by Advanced Encryption Standard (AES) block cipher algorithms. If the NAC does not use FIPS-mode or key management process that is FIPS-approved and protected by Advanced Encryption Standard (AES) block cipher algorithms, this is a finding.
Fix: F-36493r605703_fix
If the Forescout Appliance is using FIPS mode, then TLS 1.2 is set as part of that configuration and does not need to be configured manually. If not in FIPS mode, then: 1. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 2. In the Client-Server Connection, set the Minimum Supported TLS Version to TLS version 1.2.
- RMF Control
- AC-24
- Severity
- M
- CCI
- CCI-002353
- Version
- FORE-NC-000290
- Vuln IDs
-
- V-233334
- Rule IDs
-
- SV-233334r611394_rule
Checks: C-36529r605705_chk
Verify both ends are configured for secure communications between the NAC and NAC agent. If communication between the NAC and NAC agent does not use an encrypted method for protecting posture information transmitted between the devices, this is a finding.
Fix: F-36494r605706_fix
Log on to the Forescout UI. 1. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 2. In the Client-Server Connection, check the Minimum Supported TLS Version is set to TLS version 1.2.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- FORE-NC-000340
- Vuln IDs
-
- V-233335
- Rule IDs
-
- SV-233335r616546_rule
Checks: C-36530r605708_chk
Verify the policy assessment device uses TLS 1.2 to protect the confidentiality of the communication between the endpoint and the NAC. 1. Log on to the Forescout UI. 2. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 3. In the Client-Server Connection, check the Minimum Supported TLS Version is set to TLS version 1.2. If the NAC does not use TLS 1.2, at a minimum, to protect the confidentiality of information passed between the endpoint agent and the NAC for the purposes of client posture assessment, this is a finding.
Fix: F-36495r616545_fix
Log on to the Forescout UI. 1. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 2. In the Client-Server Connection, set the Minimum Supported TLS Version to TLS version 1.2.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001861
- Version
- FORE-NC-000420
- Vuln IDs
-
- V-233336
- Rule IDs
-
- SV-233336r616547_rule
Checks: C-36531r605711_chk
Verify the NAC is configured with a secondary log server in case the primary log is unreachable. 1. Log on to the Forescout UI. 2. Select Tools >> Options >>Syslog >>Syslog Triggers. 3. Verify all boxes in the NAC Events section are checked. This includes the "Include NAC policy logs" and the "Include NAC policy match/unmatch events". If the NAC is not configured with a secondary log server in case the primary log is unreachable, this is a finding.
Fix: F-36496r615857_fix
1. Log on to the Forescout UI. 2. Select Tools >> Options >> Syslog >> Syslog Triggers. 3. Check all boxes in the NAC Events section. This includes the "Include NAC policy logs" and the "Include NAC policy match/unmatch events".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- FORE-NC-000440
- Vuln IDs
-
- V-233337
- Rule IDs
-
- SV-233337r611394_rule
Checks: C-36532r605714_chk
Verify the NAC performs continuous detection and tracking of endpoint devices attached to the network. 1. Log on to the Forescout UI. 2. Go to Tools >> Options >> Appliance >> IP Assignment. 3. Check that all IP addresses that should be managed are within the IP Assignments as required by the SSP. If the NAC does not perform continuous detection and tracking of endpoint devices attached to the network, this is a finding.
Fix: F-36497r605715_fix
Log on to the Forescout UI. 1. Go to Tools >> Options >> Appliance >> IP Assignment. 2. Enter all IP addresses to be managed in the IP Assignment to enable the continuous monitoring capabilities of Forescout.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000778
- Version
- FORE-NC-000450
- Vuln IDs
-
- V-233338
- Rule IDs
-
- SV-233338r611394_rule
Checks: C-36533r605717_chk
Verify the NAC denies network connection for endpoints that cannot be authenticated using an approved method and log authentication failures. 1. Log on to Forescout UI. 2. From the Policy tab, select the Authentication and Authorization policy. 3. Find the 802.1x Authorization policy. If NAC does not have an authorization policy that denies network connection for endpoints that cannot be authenticated using an approved method and log authentication failures, this is a finding.
Fix: F-36498r605718_fix
Log on to Forescout UI. 1. From the Policy tab, select the Authentication and Authorization policy. 2. Find the 802.1x Authorization policy and click Edit. From the Sub-Rules section, check that all of the options for authentication are selected including the following: -Machine Authenticated -User+Machine Authenticated -User+Managed Machine -User+NotMachine Authenticated If these are all configured, check that the final step is not authorized by one of the previous steps, and block traffic in accordance with the SSP by selecting "Add>". 1. Give the policy a name like "Deny Access". 2. In the Condition box, click "Add" and select "802.1x RADIUS Authentication State". 3. Check the box labeled "RADIUS-Rejected", and then click "OK". 4. In the Actions box, click "Add" and select a block action in accordance with the SSP.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- FORE-NC-000460
- Vuln IDs
-
- V-233339
- Rule IDs
-
- SV-233339r611394_rule
Checks: C-36534r605720_chk
Log on using the CLIAdmin credentials established upon initial configuration. Verify FIPS mode by typing the command "fstool version". If Forescout does not use a bidirectional authentication mechanism configured with a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the endpoint device, this is a finding.
Fix: F-36499r605721_fix
To enable FIPS mode on the Forescout appliance, start by opening a secure shell to the CLI of the management appliance using Putty or another tool. Log on using the CLIAdmin credentials established upon initial configuration. To enable FIPS mode, type "fstool fips". A prompt alerting the user that FIPS 140-2 will be enabled will be displayed. Type "Yes" for FIPS to accept this prompt. Note: Use of FIPS mode is not mandatory in DoD. However, it is the primary method for mitigation of this requirement and ensuring FIPS compliance.
- RMF Control
- IA-5
- Severity
- H
- CCI
- CCI-000185
- Version
- FORE-NC-000470
- Vuln IDs
-
- V-233340
- Rule IDs
-
- SV-233340r615860_rule
Checks: C-36535r605723_chk
1. Log on using the CLIAdmin credentials established upon initial configuration. 2. Verify FIPS mode by typing the command 'fstool version'. To configure TLS: 1. Log on to the Forescout UI. 2. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 3. In the Client-Server Connection, check the Minimum Supported TLS Version is set to TLS version 1.2. If the NAC does not perform RFC 5280-compliant certification path validation for validating certificates used for TLS functions when connecting with endpoints, this is a finding.
Fix: F-36500r615859_fix
To configure FIPS Mode: 1. Log on using the CLIAdmin credentials established upon initial configuration. 2. To enable FIPS mode, type 'fstool fips'. A prompt will be generated alerting the user FIPS 140-2 will be enabled. Type "Yes" for FIPS to accept this prompt. To configure TLS: 1. Log on to the Forescout management tool. 2. Select Tools >> Option >> HPS Inspection Engine >> SecureConnector. 3. In the Client-Server Connection, set the Minimum Supported TLS Version to TLS version 1.2.