STIGQter STIGQter: STIG Summary: Symantec Edge SWG ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

The Edge SWG must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.

DISA Rule

SV-279167r1170656_rule

Vulnerability Number

V-279167

Group Title

SRG-NET-000339-ALG-000090

Rule Version

SYME-00-002600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the VPM.
2. Under the configured Web Access Layer, add a rule.
3. Under "Source", left-click then click "Set".
4. Click "Add new object".
5. Select "Group".
6. Enter the full Distinguished Name (DN) of the LDAPS group. For example: "CN=broadcom.proxyusers.gsg,OU=BROADCOM,DC=dod,DC=mil"
7. Under "Authentication Realm", select the CAC/certificate realm.
8. Click "Apply".
9. Under "Service", left-click then click "Set".
10. Select the "All HTTPS client" protocol.
11. Click "Apply".
12. Under Action, left-click then click "Set".
13. Click "Allow", then click "Apply".
14. Under "Track", left-click then click "Set".
15. Select the event log that was created previously.
16. Click "Apply".
17. Repeat the above steps for HTTP instead of HTTPS and add any additional protocols that need to be proxied.
18. Click "Apply policy".

Check Contents

In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).

Under the configured Web Access Layer, if there are not allow rules for at least HTTP and HTTPS, this is a finding.

If the allow rules do not have a specific LDAPS group used in the source column, this is a finding.

If the rule does not have the Track column set to log all access logs, this is a finding.

Vulnerability Number

V-279167

Documentable

False

Rule Version

SYME-00-002600

Severity Override Guidance

In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).

Under the configured Web Access Layer, if there are not allow rules for at least HTTP and HTTPS, this is a finding.

If the allow rules do not have a specific LDAPS group used in the source column, this is a finding.

If the rule does not have the Track column set to log all access logs, this is a finding.

Check Content Reference

M

Target Key

5725