Ivanti Policy Secure NAC Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- IVPS-NC-000001
- Vuln IDs
-
- V-284581
- Rule IDs
-
- SV-284581r1244870_rule
Checks: C-89146r1244635_chk
1. In the Ivanti Policy Secure Web UI, navigate to Users >> User Realms >> User Authentication Realms. 2. Under the General tab >> "Certificate login for authentication with a User/Directory/Attribute", verify the default "User Realm" is not in use. 3. Verify host checker policies include policies for type, resource group, and/or mission conditions. If the host checker policies are not configured with preadmissions assessment filters as defined in the NAC SSP, this is a finding.
Fix: F-89051r1244720_fix
Create endpoint security host checker policies and associate them with host enforcement policies. This is an example configuration. There are many other places where different assessment policies may be derived from in this complex system depending on the specific type of filter. However, the realm configuration will allow associate and enforcement of these policies in accordance with the SSP. 1. In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >> Host Checker. 2. Under "Policies" click "New". 3. Type the name. 4. Click "Continue". 5. Under "Rule Settings", select "Rule type". 6. Create Host Checker Rules to configure admissions assessment filters. 7. Click "Save Changes". There are default Authentication Realms to include Users and various Guest realms. These must be disabled or deleted if not used. 1. Navigate to Users >> User Realms >> User Realms to view the User Authentication Realms page. 2. Under the "General" tab, create a new user realm or modify the default user to use certificate login for authentication with a User/Directory/Attribute. 3. Under the "Authentication Policy" tab, select the "Certificate" tab, then select the radio button to only allow users with a client-side certificate signed by Trusted Client certificate authorities (CAs) to sign in. 4. Under the "Host checker" tab, locate the available policies with an action by selecting "Evaluate Policies" or "Require & Enforced" based on the site's SSP. 5. Select the "Role Mapping" tab and create a rule assessing condition and assign a specific role. Specify how to assign roles to users when they sign in. Users that are not assigned a role will not be able to sign in.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- IVPS-NC-000002
- Vuln IDs
-
- V-284582
- Rule IDs
-
- SV-284582r1244871_rule
Checks: C-89147r1244378_chk
If post admissions is not used, this is not applicable. In the Ivanti Policy Secure Web UI, navigate to Endpoint Policy >> Host Enforcer >> Host Enforcer Policies. If there are no Host Enforcer Policies created, this is a finding.
Fix: F-89052r1244619_fix
1. In the Ivanti Policy Secure Web UI, navigate to Endpoint Policy >> Host Enforcer >> Host Enforcer Policies. 2. Click "New Policy". 3. Type "Name" and "Description". 4. Specify "Resources". 5. Specify "Roles". 6. Specify "Actions" such as Allow/Deny, etc. 7. Click "Save Changes".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- IVPS-NC-000003
- Vuln IDs
-
- V-284583
- Rule IDs
-
- SV-284583r1244872_rule
Checks: C-89148r1244381_chk
In the Ivanti Policy Secure Web UI, navigate to Users >> User Realms >> User Authentication Realms. Under the "Certificate" tab, verify the radio button for "Only allow users with a client-side certificate signed by Trusted Client CAs to sign in" is on. If the system is not configured to confirm endpoint policy assessment proceeds only after the endpoint attempting access has been identified using an approved identification method, this is a finding.
Fix: F-89053r1244382_fix
Configure the Host Checker: 1. In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >>Host Checker. 2. Under the "Certificate" tab, select "Only allow users with a client-side certificate signed by Trusted Client CAs to sign in". Configure the User Authentication Realm: 1. In the Ivanti Policy Secure Web UI, navigate to Users >> User Realms >> User Authentication Realms. Note: By default, there are default Authentication Realms to include Users and various Guest realms. 2. Under the "General" tab, create a new user realm or modify the default "User" to use certificate login for authentication with a User/Directory/Attribute. 3. Under the "Certificate" tab, select the radio button for "Only allow sign-in by users with a client-side certificate signed by Trusted Client CAs". 4. Click the "Host checker" tab, then associate a policy and set as "Required & Enforced". 5. Select the "Role mapping" tab and create a rule assessing condition and assign a specific role.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- IVPS-NC-000007
- Vuln IDs
-
- V-284586
- Rule IDs
-
- SV-284586r1244873_rule
Checks: C-89151r1244621_chk
If automated remediation is not used, this is not applicable. 1. In the Ivanti Policy Secure Web UI, navigate to Endpoint Policy >> Network Access >> Radius Attributes >> Radius Return Attributes. 2. Inspect the policy to ensure it is configured with an assigned location group, roles, and remediation VLAN ID. If the remediation VLAN that is separated from trusted resources is not configured for use, this is a finding.
Fix: F-89056r1244642_fix
1. In the Ivanti Policy Secure Web UI, navigate to Endpoint Policy >> Network Access >> Radius Attributes >> Radius Return Attributes. 2. Click "New Policy". 3. Type a Name and Description. 4. Assign Location Groups to which the policy applies. 5. Expand the "Access Control Policy Settings" menu. 6. Click the "Control" radio button. 7. Click the check box for "Control Using VLAN id []" and specify the remediation or redirect VLAN. 8. Select the PPS interface to which endpoints will connect while they are assigned to the above VLAN. 9. Expand "Roles". 10. Select the role to which this policy is applicable and set it for selected below and specify designated role. 11. Click "Save Changes".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- IVPS-NC-000021
- Vuln IDs
-
- V-284587
- Rule IDs
-
- SV-284587r1244874_rule
Checks: C-89152r1244394_chk
If nonentity endpoints using MAB are not connected, this is not applicable. 1. Select Endpoint Policy >> MAC Address Realm. 2. View the configuration of at least one MAC Address Authentication realm and Role Mapping rule. If the MAC address realm is not configured and associated with role mappings, rules and a separate NPE VLAN, this is a finding.
Fix: F-89057r1244395_fix
Configure the MAC address authentication server for an authorized and separated NPE VLAN. 1. Select Authentication >> Auth. Servers. 2. Select "MAC Address Authentication" and click "New Server". Configure the MAC address authentication server configuration page and then click "Save". Configure the MAC Address Authentication Realm and Role Mapping Rules. 1. Select Endpoint Policy >> MAC Address Realm. 2. Complete the configuration page and then click "Save". Note: This realm can now be associated with roles, location groups, RADIUS client, etc. as any other realm. Direct configuration of authenticators on the Ivanti Policy server, including MAC addresses, is not permitted; thus, NPE MACs must be associated with a MAC authentication server with an LDAP server.
- RMF Control
- Severity
- M
- CCI
- CCI-004866
- Version
- IVPS-NC-000031
- Vuln IDs
-
- V-284588
- Rule IDs
-
- SV-284588r1244875_rule
Checks: C-89153r1244397_chk
1. In the Ivanti Policy Secure Web UI, navigate to Users >> User Realms >> User Realms. 2. Click the configured admin realm being used for CAC/PKI token user logins. 3. Click the "Authentication Policy" tab, then click "Limits". If the "Maximum number of sessions per user" is any number other than "1", this is a finding.
Fix: F-89058r1244398_fix
1. In the Ivanti Policy Secure Web UI, navigate to Users >> User Realms >> User Realms. 2. Click the configured user realm being used for CAC/PKI token user logins. 3. Click the "Authentication Policy" tab, then click "Limits". 4. In "Maximum number of sessions per user," type "1". 5. Click "Save Changes".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- IVPS-NC-000005
- Vuln IDs
-
- V-285223
- Rule IDs
-
- SV-285223r1244921_rule
Checks: C-89792r1244776_chk
In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >> Host Checker. If there are no Host Checker policies to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used, this is a finding.
Fix: F-89697r1244777_fix
1. In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >>Host Checker. 2. Under "Policies", click "New". 3. Type a name. 4. Click "Continue". 5. Under "Rule Settings", select "Rule type". 6. Create Host Checker rules to notify the user before proceeding with remediating the user's endpoint device when automated remediation is used. 7. Click "Save Changes".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- IVPS-NC-000004
- Vuln IDs
-
- V-285224
- Rule IDs
-
- SV-285224r1244922_rule
Checks: C-89793r1244779_chk
In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >>Host Checker. If a Host Checker policy is not configured to terminate the session or redirect to a remediation VLAN based on the site's SSP, this is a finding.
Fix: F-89698r1244780_fix
1. In the Ivanti Policy Secure Web UI, navigate to Authentication >> Endpoint Security >>Host Checker. 2. Under "Policies", click "New". 3. Type a name. 4. Click "Continue". 5. Under "Rule Settings", select "Rule type". 6. Create Host Checker rules for failed policy assessment to either terminate the session or redirect the endpoint to the remediation VLAN. 7. Click "Save Changes".