SV-104239r2_rule
V-94285
SRG-NET-000339-ALG-000090
SYMP-AG-000350
CAT II
10
Configure an approved method of multifactor authentication (such as CAC certificate authentication).
1. Log on to the Web Management Console.
2. Browse to Configuration >> Authentication.
3. Configure at least one multifactor method (such as CAC certificate authentication) per the ProxySG Administration Guide (CAC Certificate authentication configuration is covered in Chapter 52: Certificate Realm Authentication and Chapter 58: LDAP Realm Authentication).
Multiple methods of multifactor authentication are supported. Verify that an approved method is configured (such as CAC certificate authentication).
1. Log on to the Web Management Console.
2. Browse to Configuration >> Authentication.
3. Click each of the above authentication mechanisms and Verify that at least one approved multifactor authentication method is configured per the ProxySG Administration Guide (CAC Certificate authentication configuration is covered in Chapter 52: Certificate Realm Authentication and Chapter 58: LDAP Realm Authentication).
If Symantec ProxySG providing user authentication intermediary services does not implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access, this is a finding.
V-94285
False
SYMP-AG-000350
Multiple methods of multifactor authentication are supported. Verify that an approved method is configured (such as CAC certificate authentication).
1. Log on to the Web Management Console.
2. Browse to Configuration >> Authentication.
3. Click each of the above authentication mechanisms and Verify that at least one approved multifactor authentication method is configured per the ProxySG Administration Guide (CAC Certificate authentication configuration is covered in Chapter 52: Certificate Realm Authentication and Chapter 58: LDAP Realm Authentication).
If Symantec ProxySG providing user authentication intermediary services does not implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access, this is a finding.
M
3515