Any chance we can get a forum to discuss STIG concerns?
From time-to-time we get a STIG that is not documented in the released documentation for given hardware/software.
The current example I am looking for is...
------------------------------------------------------------------------------------------------------------------------------------
"Check Text: Verify the firewall stops forwarding traffic or maintains the configured security policies upon the failure of the following: system initialization, shutdown, or system abort.
If the firewall does not stop forwarding traffic or maintain the configured security policies upon the failure of system initialization, shutdown, or system abort, this is a finding.
Fix Text: Configure the firewall to stop forwarding traffic or maintain the configured security policies upon the failure of the following actions: system initialization, shutdown, or system abort."
------------------------------------------------------------------------------------------------------------------------------------
I have not been able to find any information about the traffic flow during a reboot, or system failure for the system I am using.
What is the best location to find answers on these types of topics? In the past, if I can not find documentation on a particular subject required for a STIG, I end up opening a ticket. It seems like that is a lot of overhead for something a lot of people need to do.