Skip Navigation

IIST-SV-000142: Restrict inbound connections

The IIS 10.0 web server must restrict inbound connections from non-secure zones.
This requirement applies to the Web Management Service. If the Web Management Service is not installed, this requirement is not applicable.
To check compliance with IIST-SV-000142, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Under
    Management
    , double-click
    Management Service
    .
  4. If
    Enable remote connections
    is not selected, this requirement is not applicable. If
    Enable remote connections
    is selected, review the entries under
    IP Address Restrictions
    .
  5. Verify that only known, secure IP ranges are configured as
    Allow
    .
If
IP Address Restrictions
are not configured, or IP ranges that are configured as
Allow
are not restrictive enough to prevent connections from non-secure zones, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.5 web server name.
  3. Under
    Management
    , double-click
    Management Service
    .
  4. In the
    Actions
    pane, stop the Web Management Service.
  5. Configure only known, secure IP ranges as
    Allow
    .
  6. In the
    Actions
    pane, click
    Apply
    .
  7. In the
    Actions
    pane, restart the Web Management Service.