STIGQter STIGQter: STIG Summary: Symantec ProxySG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Symantec ProxySG must implement HTTPS-console to provide replay-resistant authentication mechanisms for network access to privileged accounts.

DISA Rule

SV-104527r1_rule

Vulnerability Number

V-94697

Group Title

SRG-APP-000156-NDM-000250

Rule Version

SYMP-NM-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable TLS management services.

1. Log on to Web Management Console.
2. Click Configuration >> Services >> Management Services.
3. Make sure that "HTTPS-Console" is "Enabled".
4. Uncheck "Enabled" next to that "HTTP-Console".
5. Click "Apply".

Check Contents

Verify only TLS management services are enabled.

1. Log on to Web Management Console.
2. Click Configuration >> Services >> Management Services.
3. Verify "HTTP-Console" is not enabled and that "HTTPS-Console" is enabled.

If Symantec ProxySG does not implement HTTPS-console, this is a finding.

Vulnerability Number

V-94697

Documentable

False

Rule Version

SYMP-NM-000230

Severity Override Guidance

Verify only TLS management services are enabled.

1. Log on to Web Management Console.
2. Click Configuration >> Services >> Management Services.
3. Verify "HTTP-Console" is not enabled and that "HTTPS-Console" is enabled.

If Symantec ProxySG does not implement HTTPS-console, this is a finding.

Check Content Reference

M

Target Key

3517

Comments