SV-237057r639618_rule
V-237057
SRG-NET-000401-ALG-000127
AADC-AG-000122
CAT II
10
The following commands configure the ADC to restrict the HTTP methods:
slb template waf [template-name]
allowed-http-methods GET POST HEAD PUT DELETE CONNECT PURGE
Note: GET and POST are the default values and are the safest choices. Restricting the methods to GET and POST is recommended.
If the ADC is not used to load balance web servers, this is not applicable. Interview the device administrator to determine which WAF template is used for web servers.
Review the device configuration.
The following command displays the configuration and filters the output on the WAF template section:
show run | sec slb template waf
If there is no WAF template, this is a finding.
If the WAF template allows the HTTP TRACE method, this is a finding.
V-237057
False
AADC-AG-000122
If the ADC is not used to load balance web servers, this is not applicable. Interview the device administrator to determine which WAF template is used for web servers.
Review the device configuration.
The following command displays the configuration and filters the output on the WAF template section:
show run | sec slb template waf
If there is no WAF template, this is a finding.
If the WAF template allows the HTTP TRACE method, this is a finding.
M
5285