SV-100611r1_rule
V-89961
SRG-APP-000098-WSR-000060
VRAU-TC-000215
CAT II
10
Navigate to and open /etc/vcac/server.xml.
Navigate to and locate <Host>.
Configure the <Host> node with the <RemoteIpValve> below.
Note: The "RemoteIpValve" should be configured as follows:
<Valve className="org.apache.catalina.valves.RemoteIpValve"
httpServerPort="80"
httpsServerPort="443"
internalProxies="127\.0\.0\.1"
protocolHeader="x-forwarded-proto"
proxiesHeader="x-forwarded-by"
remoteIpHeader="x-forwarded-for"/>
At the command prompt, execute the following command:
tail /storage/log/vmware/vcac/access_log.YYYY-MM-dd.txt
Note: Substitute the actual date in the file name.
If actual client IP information, not load balancer or proxy server, is not being recorded, this is a finding.
V-89961
False
VRAU-TC-000215
At the command prompt, execute the following command:
tail /storage/log/vmware/vcac/access_log.YYYY-MM-dd.txt
Note: Substitute the actual date in the file name.
If actual client IP information, not load balancer or proxy server, is not being recorded, this is a finding.
M
3439