STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 6 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Tanium 7.x Security Technical Implementation Guide

V-253849

CAT II (Medium)

Firewall rules must be configured on the Tanium Zone Server for Client-to-Zone Server communications.

Rule ID

SV-253849r1099952_rule

STIG

Tanium 7.x Security Technical Implementation Guide

Version

V2R3

CCIs

CCI-000382

Discussion

In customer environments using the Tanium Zone Server, a Tanium Client may be configured to point to a Zone Server instead of a Tanium Server. The communication requirements for these Clients are identical to the Server-to-Client requirements. Without proper firewall configurations, proper TCP communications may not take place as necessary for application functionality. Additionally, without proper configuration, organizations may lose complete visibility into endpoints that cannot connect directly to the Tanium Server.

Check Content

Note: If a Zone Server is not being used, this is not applicable.

1. Consult with the Tanium system administrator to verify which firewall is being used as a host-based firewall on the Tanium Zone Server.

2. Access the host-based firewall configuration on the Tanium Zone Server.

3. Validate a rule exists for the following:

Port Needed: Tanium Clients to Zone Server over TCP port 17472, bidirectionally.

If a host-based firewall rule does not exist to allow TCP port 17472, bidirectionally, from Tanium Clients to the Tanium Zone Server, this is a finding.

Fix Text

Consult with the personnel who maintain the Enterprise Security Suite to configure host-based and network firewall rules to allow the following:

Tanium Clients or Zone Clients over TCP port 17472, bidirectionally.