Comments (5)
This will be fixed in our next release (going out this week).
from devopskit.
@samhodgkinson Could you please post the detailed error that you got. Azure_VNet_NetSec_Justify_IPForwarding_for_NICs is the control Id and not an error.
from devopskit.
Your right; but the issue here is, IPForwarding is only enabled on the interface. I have scanned a template just containing VNET/Subnet/NSG. I should only get an IPForwarding alert/error when an interface is deployed and the enableIPForwarding parameter is set to $true.
Interface Schema
https://docs.microsoft.com/en-us/azure/templates/microsoft.network/2018-11-01/networkinterfaces
Network Schema
https://docs.microsoft.com/en-us/azure/templates/microsoft.network/2018-11-01/virtualnetworks
I will run the scan later and add a screen grab.
from devopskit.
same issue here:
ControlId : Azure_VNet_NetSec_Justify_IPForwarding_for_NICs
FeatureName : VirtualNetwork
Status : Failed
SupportedResources : Microsoft.Network/virtualNetworks , Microsoft.Network/networkInterfaces
Severity : High
PropertyPath : Not found
LineNumber : -1
CurrentValue :
ExpectedProperty : $.properties.enableIPForwarding
ExpectedValue : 'False'
ResourcePath : resources[0]
ResourceLineNumber : 86
Description : Use of IP Forwarding on any NIC in a virtual network should be scrutinized
FilePath : D:\a\1\s\src\Generic-VNet-and-SNet\vnet.json
from devopskit.
Yep getting the same false error for Vnet resource. If I add the expected property then it passes the azsk validation but then in deployment it will fail as its not a valid schema for Vnet.
##[error]BadRequest: { "error": { "code": "InvalidRequestFormat", "message": "Cannot parse the request.", "details": [ { "code": "InvalidJson", "message": "Could not find member 'enableIPForwarding' on object of type 'VirtualNetworkProperties'. Path 'properties.enableIPForwarding', line 1, position 115." } ] } } undefined
from devopskit.
Related Issues (20)
- Feature Request exclude passed controli ds from log
- Override values for Azsk.Azdo
- Support AzSKARMTemplateChecker task on Ubuntu agent HOT 1
- Secure DevOps Kit (AzSK) CICD Extensions - AzSKARMTemplateChecker task fails if template does not contain supported resources HOT 2
- Fail to upgrade Org Policy with AzSK from 4.4.0 to 4.10.0 HOT 3
- Azure_Storage_DP_Encrypt_In_Transit Failing unused property in Storage Account Blobservices ARM Template HOT 1
- Not showing azsk monitoring solution in Azure log analytics workspace HOT 1
- Azure_AppService_Audit_Enable_Logging_and_Monitoring fails when two Diagnostics settings are configured, but only one has all required logs enabled HOT 2
- Bypass 'Get-AzSKAzureServicesSecurityStatus' cmdlet's confirmation prompt for attestation HOT 2
- AzSK version 4.12 Security Status Report does not create SecurityEvaluationData json
- Module not catalog signed HOT 1
- AzSK 4.14 Install-AzSKContinuousAssuranceForCluster: Any way to run in a non-interactive mode
- Installation error HOT 1
- Logic app accesscontrol validations HOT 1
- Enable Eventhub output for Central CAs HOT 2
- Support for Azure Blueprints? HOT 1
- AzTS exceptions - System.ArgumentException: Requested value 'CDN' was not found. HOT 2
- Intermittent Error Thrown-Unable to deserialize the response. HOT 5
- APIM ARM template generated using Azure CLI dotnet command is giving error while deploying through Azure devops
- ARMTemplateChecker - Enable Azure AD admin for the SQL Database - False positive with linked templates HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from devopskit.