Verify Any Configured IPSec Tunnel Connections
An XCCDF Rule
Description
Libreswan provides an implementation of IPsec
and IKE, which permits the creation of secure tunnels over
untrusted networks. As such, IPsec can be used to circumvent certain
network requirements such as filtering. Verify that if any IPsec connection
(conn
) configured in /etc/ipsec.conf
and /etc/ipsec.d
exists is an approved organizational connection.
warning alert: Warning
Automatic remediation of this control is not available due to the unique
requirements of each system.
Rationale
IP tunneling mechanisms can be used to bypass network filtering.
- ID
- xccdf_org.ssgproject.content_rule_libreswan_approved_tunnels
- Severity
- Medium
- References
- Updated