STIGQter STIGQter: STIG Summary: Symantec Edge SWG ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

In the event of a system failure of the ALG function, the Edge SWG must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted.

DISA Rule

SV-279187r1170651_rule

Vulnerability Number

V-279187

Group Title

SRG-NET-000236-ALG-000119

Rule Version

SYME-00-005900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Go to "Logging and Access Logging".
3. Scroll down to "Logs" and click "Edit" on the Main log.
4. Under "Upload Client", select "SCP".
5. Click "Open Settings" and configure the following variables: host, port, full path, username, and password.
6. Click "Apply and Test Upload". If there are connection issues, fix these before continuing.
7. Under "Transmission Parameters", select a signing certificate. This signing certificate must be the certificate used for SSL Proxying issued by the DOD WCF Certificate Authority (CA).
8. Check "Text File".
9. Under "Upload Schedule" select "Periodically".
10. Then, choose 5 seconds between connect attempts.
11. Select the "Daily interval" and select a time that works for the site SCP server.
12. Click "Upload Now" to test if the upload works. If there are connection issues, fix these before continuing.
13. Click "Apply and Save".

Check Contents

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Go to "Logging and Access Logging".
3. Scroll down to "Logs" and click "Edit" on the Main log.

If there is no upload client configured, this is a finding.

Under upload schedule, if the is a schedule for "Periodically" is not selected, then this is a finding.

Vulnerability Number

V-279187

Documentable

False

Rule Version

SYME-00-005900

Severity Override Guidance

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Go to "Logging and Access Logging".
3. Scroll down to "Logs" and click "Edit" on the Main log.

If there is no upload client configured, this is a finding.

Under upload schedule, if the is a schedule for "Periodically" is not selected, then this is a finding.

Check Content Reference

M

Target Key

5725