STIGQter STIGQter: STIG Summary: Symantec ProxySG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Symantec ProxySG must compare internal information system clocks at least every 24 hours with an authoritative time server.

DISA Rule

SV-104501r1_rule

Vulnerability Number

V-94671

Group Title

SRG-APP-000371-NDM-000296

Rule Version

SYMP-NM-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Symantec ProxySG to use authoritative NTP servers (the NTP protocol itself enforces periodic checks at least every 24 hours).

1. Log on to the Web Management Console.
2. Select "Configuration", then "General", then "Clock".
3. Enter the desired time sync period into the "Query interval (minutes) field and click Apply.
4. Click "NTP", then "New", then "Add" and enter each desired authoritative time server.
5. Click "Apply".

Check Contents

Verify the Symantec ProxySG is configured to use authoritative NTP servers (the NTP protocol itself enforces periodic checks at least every 24 hours).

1. Log on to the Web Management Console.
2. Click Configuration >> General >> Clock.
3. Confirm that the value of the "Query interval (minutes)" field is at least 1440 (24 hours in minutes).
4. Click "NTP", and confirm that the desired authoritative time servers are present.

If Symantec ProxySG does not compare internal information system clocks at least every 24 hours with an authoritative time server, this is a finding.

Vulnerability Number

V-94671

Documentable

False

Rule Version

SYMP-NM-000100

Severity Override Guidance

Verify the Symantec ProxySG is configured to use authoritative NTP servers (the NTP protocol itself enforces periodic checks at least every 24 hours).

1. Log on to the Web Management Console.
2. Click Configuration >> General >> Clock.
3. Confirm that the value of the "Query interval (minutes)" field is at least 1440 (24 hours in minutes).
4. Click "NTP", and confirm that the desired authoritative time servers are present.

If Symantec ProxySG does not compare internal information system clocks at least every 24 hours with an authoritative time server, this is a finding.

Check Content Reference

M

Target Key

3517

Comments