SV-279177r1170662_rule
V-279177
SRG-NET-000061-ALG-000009
SYME-00-004200
CAT II
10
1. In the Edge SWG Web UI, navigate to the VPM.
2. Select the Web Access Layer.
3. Click the first block or allow rule.
4. Left-click "Track".
5. Click "Set".
6. Click "Add New Object".
7. Click "Event Log".
8. Under "Details" add the following:
$(appliance.name)$(appliance.primary_address)$(c-ip)$(c-port)$(c-uri)$(c-uri-address)$(c-uri-cookie-domain)$(c-uri-extension)$(c-uri-host)$(c-uri-hostname)$(c-uri-path)$(c-uri-pathquery)$(client.address)$(client.certificate.subject)$(client.host)$(client.public_address)$(cs-auth-group)$(cs-categories-policy)$(date)$(user.name)$(user.x509.subject)
9. Under "Category", click "All".
10. Under "Display Options", click "Both".
11. Click "Apply".
12. Repeat these steps for each rule under the Web Access Layer.
13. Click "Apply Policy".
1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Go to "Logging and Event Logging".
3. Scroll down to "syslog loghosts".
4. Click "Add Loghost".
5. Select "TLS".
6. Enter the hostname of the syslog server.
7. Enter the port. For TLS, it is normally 6514.
8. Select the SSL Device Profile that will be used. (Note: The SSL device profile must include the CA certificate chain that signed the certificate of the syslog server if it is different from the ones that signed the web server certificate).
1. In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).
2. Navigate to "Administration and Event Logging".
3. Scroll down to "Syslog Loghosts".
If there is no Web Access Layer this is a finding.
If there is a Web Access Layer, but the Track is not set or not configured, this is a finding.
If no log hosts are configured, this is a finding.
V-279177
False
SYME-00-004200
1. In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).
2. Navigate to "Administration and Event Logging".
3. Scroll down to "Syslog Loghosts".
If there is no Web Access Layer this is a finding.
If there is a Web Access Layer, but the Track is not set or not configured, this is a finding.
If no log hosts are configured, this is a finding.
M
5725