Module 4: Network Configuration & Firewalling
This directory contains network security architectures, active directory port configurations, and network isolation boundaries.
Technical Hardening Controls
REQ-NET-001 - Configure Active Directory Port Matrix Establishes the minimum permitted ports for Domain Controllers, Member Servers, and Client Workstations, ensuring perimeter and local firewalls block unauthorized inbound traffic.
REQ-NET-002 - Restrict RPC Dynamic Ports Binds core directory services (NTDS, Netlogon, DFSR) to specific static ports to allow precise network firewall controls while maintaining the system-wide dynamic RPC port range at default values to prevent socket exhaustion.
REQ-NET-003 - Configure Workstation and Server Isolation Configures local firewall rules on workstations and servers to block inbound SMB, RPC, RDP, and WinRM from peer systems to prevent lateral movement.
REQ-NET-004 - Configure IPsec Domain Isolation Enforces IPsec Connection Security Rules to authenticate and encrypt traffic within the domain boundary.
REQ-NET-005 - Harden IPsec Cryptographic Configurations Restricts permitted IPsec cryptography suites to secure options (AES-256 and DH Group 19/20) for Phase 1 and Phase 2 negotiations.
REQ-NET-006 - Harden TLS Protocols, Cipher Suites, and Elliptic Curves Disables legacy SSL/TLS versions, enforces TLS 1.2/1.3, orders strong cipher suites, and prioritizes secure elliptic curves.
REQ-NET-007 - Enforce SMBv3 Security and Digitally Sign/Encrypt Communications Disables legacy SMB dialects, enforces SMBv3, and mandates message signing and encryption to protect communications and prevent relay attacks.
REQ-NET-008 - Configure Firewall Logging and Operational Settings Enforces Windows Defender Firewall state, sets default inbound block policies, disables local rule merging on Domain Controllers, and configures detailed dropped packet logging to improve security visibility and forensic capabilities.
REQ-NET-009 - Configure Hardened UNC Paths and LDAP Client Signing Enforces mutual authentication and SMB signing for GPO folder structures (SYSVOL/NETLOGON), restricts workstation guest logons, and requires outgoing LDAP client signing.
REQ-NET-010 - Harden WinRM Service and Restrict Remote RPC Clients Disables Basic and Digest authentication, forces encrypted WinRM communications, restricts WinRM credential caching, and blocks anonymous RPC connections.
REQ-NET-011 - Configure WMI Static Port and Service Hardening Binds the WMI service to static TCP port 24158, enforces DCOM packet privacy, isolates execution to a standalone host process, and restricts inbound firewall rules to authorized management subnets.
REQ-NET-012 - Configure RPC Filters for Named Pipes Enforces Windows Firewall RPC Filters to block administrative queries and code execution over SMB named pipes (e.g. SCM, Task Scheduler) from unauthorized subnets.
REQ-NET-013 - Block Management Traffic Between Domain Controllers Excludes Domain Controller IP addresses from allowed management rules (RDP, WinRM, WMI, ADWS) to prevent lateral movement between Tier 0 directory servers.