Control DisableServiceAccess

URI: DisableServiceAccess

Package: NetworkConnectivity

< prev | next >

Description: Signifies that firewall policy exceptions allowing access to services have been removed. This prevents client-service connections if and only if the default policy is to block other connections.

Interface

The interface between a Host and a Logical Subnet. Represents a possible point of control and a target for attack. If the Logical Subnet is an IP network, the Interface also represents the existence of an IP address.

LogicalSegment

A base class representing a route through a Host between any two distinct Logical Subnets of any kind.

CSG-DisablePortForwarding-Runtime

If device Gateway blocks unsolicited connections into private subnet ToSubnet, port forwarding is used to allow access to services by legitimate clients. This strategy may represent a run-time adaptation in response to a threat, or a permanent restriction introduced by design or in accordance with an operational policy or user preference. It also triggers threats representing side effects that would be caused by such a restriction.

CSG-DisableServiceAccess-Runtime

Apply a default firewall rule at host Host to drop messages sent to services running on the host from subnet LogicalSubnet. This strategy may represent a run-time adaptation in response to a threat, or a permanent restriction introduced by design or in accordance with an operational policy or user preference. It also triggers threats representing side effects that would be caused by such a restriction, which affect access to services running on Host but not other uses of its connection to LogicalSubnet.