Ivanti Policy Secure AAA Services Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- IVPS-AA-000024
- Vuln IDs
-
- V-284441
- Rule IDs
-
- SV-284441r1244816_rule
Checks: C-89006r1244535_chk
1. In the Web UI, navigate to Signing In >> Authentication Protocol Sets. 2. View the protocol sets for 802.1X and Cert Auth. If an EAP method is listed other than EAP-TLS, this is a finding.
Fix: F-88911r1244536_fix
1. In the Web UI, navigate to Signing In >> Authentication Protocol Sets. 2. From the global view, view the protocol sets for 802.1X and Cert Auth. 3. Configure EAP-TLS.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- IVPS-AA-000026
- Vuln IDs
-
- V-284442
- Rule IDs
-
- SV-284442r1244818_rule
Checks: C-89007r1244630_chk
1. In the Web UI, navigate to Endpoint Policy >> Radius Client. 2. Review the configuration for each RADIUS Client. 3. Verify "Shared Secret" is set as a required field. If "Shared Secret" is not set for all defined RADIUS Clients, this is a finding.
Fix: F-88912r1244631_fix
1. In the Web UI, navigate to Endpoint Policy >> Radius Client. 2. Enter "Shared Secret" for each defined RADIUS client.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- IVPS-AA-000027
- Vuln IDs
-
- V-284443
- Rule IDs
-
- SV-284443r1244819_rule
Checks: C-89008r1244541_chk
1. In the Web UI, navigate to Network >> Internal >> Settings. 2. Verify the IP address for the "Internal Interface" is set to an IP address of a separate network segment rather than the production network. If Ivanti Policy Secure is not configured for network separation from the trusted network segments, this is a finding.
Fix: F-88913r1244542_fix
1. In the Web UI, navigate to Network >> Internal >> Settings. 2. Set the IP address for the "Internal Interface" to the address of a network segment separate from the production network (this network may have services such as AD, web servers, etc.).
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000764
- Version
- IVPS-AA-000010
- Vuln IDs
-
- V-284444
- Rule IDs
-
- SV-284444r1244802_rule
Checks: C-89009r1244544_chk
1. Navigate the URL(s) used for users to login. 2. Verify users are prompted for their credentials upon signing in and cannot bypass the sign-in process. If the device does not require users be individually authenticated, this is a finding.
Fix: F-88914r1244623_fix
Create the User Role to define what actions the user can perform once logged in. 1. Navigate to Users >> User Roles. 2. Click "New Role" and give it a name. 3. Under "Access Features", check the boxes for the services needed (e.g., VPN Tunneling or Web). Configure the Authentication Server so the credentials can be verified. 1. Navigate to Authentication >> Auth. Servers. 2. Select the server type from the dropdown and click "New Server". 3. Enter the server details and click "Save". Create the User Realm to connect the user to the authentication server and the role. 1. Navigate to Users >> User Realms. 2. Click "New Realm" and give it a name. 3. Authentication: Select the server created previously. 4. Directory/Attribute: Select the same server to look up group memberships for role mapping. 5. Click "Save Changes". Set up Role Mapping Rules to map the user to a group in the LDAP server. 1. While still in the new Realm, click the "Role Mapping" tab. 2. Click "New Rule". 3. Rule based on: Select Group Membership (if using AD) or Custom Expression. 4. Condition: Select the AD group the nonadministrative users belong to. 5. Assign Role: Select the role created in a previous step. 6. Click "Save Changes". Create a Sign-In Policy to provide a URL for the users to log in. 1. Navigate to Authentication >> Signing In >> Sign-in Policies. 2. Click "New URL". 3. User type: Select Users (not Administrators). 4. Sign-in URL: Specify a path (e.g., */staff-login). 5. Authentication Realm: Select "Corporate_Network_Realm". 6. Click "Save Changes".