SV-237034r639549_rule
V-237034
SRG-NET-000088-ALG-000054
AADC-AG-000026
CAT III
10
The following command enables the device to send an SNMP trap when the health monitor shows the connection to the server is down:
snmp-server enable traps slb server-down
The following command enables the device to send an SNMP trap when the health monitor shows the connection to the server is up:
snmp enable traps slb server-up
The following command creates a health monitor for UDP 514 (the Syslog port):
health monitor [monitor name]
method udp port 514
The following command creates a Server Load Balancing instance and assigns a health monitor to it:
slb server server-name [ipaddr | hostname]
health-check [monitor]
Review the device configuration.
The following command shows the configured Server Load Balancing instances:
show run | sec slb
If no Server Load Balancing instance is configured with a health check to the Syslog server, this is a finding.
The following command shows the device configuration and filters the output on the string "snmp":
show run | inc snmp
This will include which SNMP traps the device is configured to send.
If the output does not include "snmp-server enable traps slb server-down", this is a finding.
V-237034
False
AADC-AG-000026
Review the device configuration.
The following command shows the configured Server Load Balancing instances:
show run | sec slb
If no Server Load Balancing instance is configured with a health check to the Syslog server, this is a finding.
The following command shows the device configuration and filters the output on the string "snmp":
show run | inc snmp
This will include which SNMP traps the device is configured to send.
If the output does not include "snmp-server enable traps slb server-down", this is a finding.
M
5285