STIGQter STIGQter: STIG Summary: Symantec Edge SWG ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

The Edge SWG must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.

DISA Rule

SV-279176r1170660_rule

Vulnerability Number

V-279176

Group Title

SRG-NET-000053-ALG-000001

Rule Version

SYME-00-004100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the VPM.
2. Navigate to the Proxy Auth CPL Layer.
3. Under a new <Proxy> section, add the following line. Ensure it is indented:
FORCE_DENY user.login.count=4.. user.login.log_out(yes)

Note: Login count is organizationally defined, so "4" can be changed to what the site requires.

Check Contents

1. In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).
2. Navigate to the Proxy Auth CPL Layer.

Under a <Proxy> section, if there is no text that contains a user.login.count, this is a finding.

Vulnerability Number

V-279176

Documentable

False

Rule Version

SYME-00-004100

Severity Override Guidance

1. In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).
2. Navigate to the Proxy Auth CPL Layer.

Under a <Proxy> section, if there is no text that contains a user.login.count, this is a finding.

Check Content Reference

M

Target Key

5725