STIGQter STIGQter: STIG Summary: Ivanti Connect Secure VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Oct 2025:

The ICS must be configured to send user traffic log data to redundant central log server.

DISA Rule

SV-258592r930464_rule

Vulnerability Number

V-258592

Group Title

SRG-NET-000334-VPN-001260

Rule Version

IVCS-VN-000305

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Direct user access log events to the central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings.
1. Under "Select Events to Log", check all items.
2. Under "Syslog Servers", add an IP address/server name/IP.
3. Set the facility to "LOCAL0".
4. Set type to "TLS".
5. If a client cert is required for the syslog server, select the client certificate to use for the syslog traffic. If none exists, import the DOD-signed client key pair to the ICS under System >> Configuration >> Certificates >> Client Auth Certificates.
6. Set the standard filer.
7. Set the source interface as either the management or internal interface.
8. Click "Add".
9. Click "Save Changes".
10. Repeat these steps to add a redundant syslog server for user log events.

Check Contents

Verify user access log events are being sent to the central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings.
1. Under "Select Events to Log", verify all items are checked.
2. Under "Syslog Servers", verify redundant server name/IP address, facility of LOCAL0, type TLS, and the source interface are defined.

If the ICS must be configured to send admin log data to redundant central log server, this is a finding.

Vulnerability Number

V-258592

Documentable

False

Rule Version

IVCS-VN-000305

Severity Override Guidance

Verify user access log events are being sent to the central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings.
1. Under "Select Events to Log", verify all items are checked.
2. Under "Syslog Servers", verify redundant server name/IP address, facility of LOCAL0, type TLS, and the source interface are defined.

If the ICS must be configured to send admin log data to redundant central log server, this is a finding.

Check Content Reference

M

Target Key

5559