STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM DataPower Network Device Management Security Technical Implementation Guide

V-65189

CAT II (Medium)

The DataPower Gateway must not use 0.0.0.0 as the management IP address.

Rule ID

SV-79679r1_rule

STIG

IBM DataPower Network Device Management Security Technical Implementation Guide

Version

V1R2

CCIs

CCI-001368

Discussion

If 0.0.0.0 as the management IP address, the DataPower appliance will listen on all configured interfaces for management traffic. This can allow an attacker to gain privileged-level access from an untrusted network.

Check Content

Using an administrator account, log on to the default domain of the appliance.

Navigate to Network >> Management >> Web Management Service.

View the Local Address field; if the value is “0.0.0.0”, this is a finding.

Fix Text

To configure the DataPower appliance for web management:

Using an administrator account, log on to the default domain of the appliance.

On the Configure Web Management Service screen, complete the required information.

Set the Administrative state to “enabled”.

For the Local Address, use the IP address from the management subnet assigned to the unit.