A firewall or router rule must block all ingress and egress traffic from the enclave perimeter to the MFD or Network Printer.
An XCCDF Rule
Description
<VulnDiscussion>Access to the MFD or printer from outside the enclave network could lead to a denial of service caused by a large number of large print files being sent to the device. Ability for the MFD or printer to access addresses outside the enclave network could lead to a compromise of sensitive data caused by forwarding a print file to a location outside of the enclave network. This also prevents accidental implementation of a “call-home” feature that is not allowed.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-7001r2_rule
- Severity
- Medium
- Updated
Remediation - Manual Procedure
Configure a firewall or router rule to block all ingress and egress traffic from the enclave perimeter to the MFD or Network Printer.