STIGQter STIGQter: STIG Summary: Ivanti Connect Secure VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Oct 2025:

The ICS must be configured to forward all log failure events where the detection and/or prevention function is unable to write events to local log record or send an SNMP trap that can be forwarded to the SCA and ISSO.

DISA Rule

SV-258593r930467_rule

Vulnerability Number

V-258593

Group Title

SRG-NET-000335-VPN-001270

Rule Version

IVCS-VN-000310

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Event logs are also updated to local logs by default in addition to the central syslog server. However, if the site uses SNMP, the following must be configured since SNMP is disabled by default.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
1. Under "SNMP Version data", select "v3".
2. Under "Agent Properties", check "SNMP Traps".
3. Under "Agent Properties", configure a System Name, Location, and Contact.
4. Under "User 1", type in a valid username. Select "AuthPriv".
- The auth protocol must be set to at least SHA. Type the Auth Password.
- The priv protocol must be set to at least CFB-AES-128. Type in the priv password.
5. Under "Trap Thresholds", ensure "Check Frequency" is 180 seconds, "Log Capacity" is 75%, "Users" is 100%, "Physical Memory" is 0%, "Swap Memory" is 0%, "Disk" is 75%, "CPU" is 0%, and "Meeting Users" is 100%.
6. Under "Optional Traps", check the boxes for "Critical and Major Log Events".
7. Under "SNMP Trap Servers", configure an IPv4/IPv6 address for the valid trap server/receiver, type in the port (default is 162), and select the user to use (use the user from step #4 above).

Check Contents

If SNMP is used, verify the configuration is compliant. If SNMP is not used, this is not a finding.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
1. Under "Agent Properties", verify "SNMP Traps" is checked.
2. Under "SNMP Version data", verify "v3" is selected.
3. Under "User 1", verify a user configuration in AuthPriv is using at least SHA and CFB-AES-128.
4. Verify "Optional Traps Critical and Major Log Events" are checked.
5. Verify the SNMP server IPv4/IPv6 address is configured under "SNMP Trap Servers".

If SNMP is incorrectly configured, this is a finding.

Vulnerability Number

V-258593

Documentable

False

Rule Version

IVCS-VN-000310

Severity Override Guidance

If SNMP is used, verify the configuration is compliant. If SNMP is not used, this is not a finding.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
1. Under "Agent Properties", verify "SNMP Traps" is checked.
2. Under "SNMP Version data", verify "v3" is selected.
3. Under "User 1", verify a user configuration in AuthPriv is using at least SHA and CFB-AES-128.
4. Verify "Optional Traps Critical and Major Log Events" are checked.
5. Verify the SNMP server IPv4/IPv6 address is configured under "SNMP Trap Servers".

If SNMP is incorrectly configured, this is a finding.

Check Content Reference

M

Target Key

5559