The VPN provider shall by default not establish routes between different client endpoints.
#### 5.2.10.2 **MI-EISO**: No route between different endpoints
#### 5.2.10.2 MI-EISO: No route between different endpoints
The VPN provider shall by default not establish routes between different client endpoints.
@@ -731,13 +731,13 @@ The VPN provider shall by default not establish routes between different client
|------------------|----------------------|
| all | EISO |
### 5.2.11 **TR-TRAF**: No traffic through the node unless explicitly approved
### 5.2.11 TR-TRAF: No traffic through the node unless explicitly approved
#### 5.2.11.1 Requirement
The VPN client shall not route traffic through the endpoint from sources/destinations other than the endpoint without the user's explicit informed consent, and such routing shall not be necessary for the use of any unrelated function.
#### 5.2.11.2 **MI-TRAF-1**:
#### 5.2.11.2 MI-TRAF-1:
The VPN client shall not implement the capability for routing traffic from sources/destinations other than the endpoint through an endpoint.
@@ -748,7 +748,7 @@ The VPN client shall not implement the capability for routing traffic from sourc
* Verdict: No traffic originating from the VPN provider for sources/destinations other than the endpoint => PASS, otherwise FAIL
* Evidence: Packet capture with annotations of origin of packet
#### 5.2.11.3 **MI-TRAF-2**:
#### 5.2.11.3 MI-TRAF-2:
The VPN client shall disable by default the capability for routing traffic from sources/destinations other than the endpoint through an endpoint.
@@ -759,7 +759,7 @@ The VPN client shall disable by default the capability for routing traffic from
* Verdict: No traffic originating from the VPN provider for sources/destinations other than the endpoint => PASS, otherwise FAIL
* Evidence: Packet capture with annotations of origin of packet
#### 5.2.11.4 **MI-TRAF-3**:
#### 5.2.11.4 MI-TRAF-3:
The VPN client shall alert the user if traffic if the endpoint is allowing traffic from sources/destinations other than the endpoint to be routed through the endpoint.
@@ -770,7 +770,7 @@ The VPN client shall alert the user if traffic if the endpoint is allowing traff
* Verdict: User receives some alert or notification that clearly indicates forwarding is enabled => PASS, FAIL
* Evidence: Record of UI change
#### 5.2.11.5 **MI-TRAF-4**:
#### 5.2.11.5 MI-TRAF-4:
The VPN client shall not require routing of traffic from sources/destinations other than the endpoint to use services that do not require such routing.
@@ -793,13 +793,13 @@ The VPN client shall not require routing of traffic from sources/destinations ot