SV-233329r615867_rule
V-233329
SRG-NET-000088-NAC-000440
FORE-NC-000230
CAT II
10
Configure Syslog server with TCP, as well as configure Syslog to alert if the communication between the Syslog server and the Forescout appliance loses connectivity.
1. Go to Tools >> Options >> Syslog.
2. Click Add/Edit.
3. Configure the Syslog:
- Syslog Server IP address
- Server Port
- Server Protocol set to TCP
- Check the Use TLS setting
- Configure the Identity, Facility, and Severity.
4. Click "OK".
5. Click "Apply".
1. Go to Tools >> Options >> Syslog.
2. Verify the Server Protocol is set to TCP.
3. Verify "Use TLS" setting is set.
4. Verify the "Identity, Facility, and Severity" setting is configured.
If Forescout does not use TCP for the syslog protocol, this is a finding.
V-233329
False
FORE-NC-000230
1. Go to Tools >> Options >> Syslog.
2. Verify the Server Protocol is set to TCP.
3. Verify "Use TLS" setting is set.
4. Verify the "Identity, Facility, and Severity" setting is configured.
If Forescout does not use TCP for the syslog protocol, this is a finding.
M
5250