SV-233323r611394_rule
V-233323
SRG-NET-000333-NAC-001340
FORE-NC-000150
CAT II
10
Configure Syslog server with TCP, as well as configure Syslog to alert if the communication between the Syslog server and the Forescout appliance loses connectivity.
1. Go to Tools >> Options >> Syslog.
2. Click Add/Edit.
3. Configure the Syslog:
- Syslog Server IP address
- Server Port
- Server Protocol set to TCP
- Check the Use TLS setting
- Configure the Identity, Facility, and Severity.
4. Click "Ok".
5. Click "Apply".
Note: A secondary syslog server is required to fully meet this requirement (covered in NDM STIG). Use the same instructions to configure a second syslog.
1. Go to Tools >> Options >> Syslog.
2. Verify a central log server's IP address is configured.
If Forescout does not configured to log records onto a centralized events server, this is a finding.
V-233323
False
FORE-NC-000150
1. Go to Tools >> Options >> Syslog.
2. Verify a central log server's IP address is configured.
If Forescout does not configured to log records onto a centralized events server, this is a finding.
M
5250