STIGQter STIGQter: STIG Summary: Symantec Edge SWG ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

The Edge must implement load balancing to limit the effects of known and unknown types of denial-of-service (DoS) attacks.

DISA Rule

SV-279219r1170647_rule

Vulnerability Number

V-279219

Group Title

SRG-NET-000362-ALG-000120

Rule Version

SYME-00-009800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implementation of multiple Edge SWG nodes must be done in a transparent proxy using an ethernet bridge. This is done using the Symantec Integrates Secure Gateway (ISG).

1. Log in to the ISG SSH CLI.
2. Enter "enable" and "configure terminal".
3. Enter "bridge view". There should be no interfaces added to a bridge.
4. Enter "bridge edit passthru-2:0 mode fail-closed".
5. Create the network definition and type "network-definition create <NAME>".
6. Add the bridge to the network definition and type "network-definition edit <NAME> add mode reserved bridges passthru-2:0".
7. Add the definition to the Edge SWG image by typing: "applications edit <SWG NAME> network-definition <NAME>".
8. Start the image by entering the command "applications start<SWG NAME>".
9. Repeat these steps for any other Edge SWGs being added for high availability.

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Go to "Network and Adapters".
3. Scroll down to the Bridge section and click the "pass-through-2:0" bridge.
4. Click "Add Interface".
5. Find the two interfaces being used and add them.
6. Click "Apply and Save".

Check Contents

Implementation of multiple Edge SWG nodes must be done in a transparent proxy using an ethernet bridge. This is done using the Symantec Integrates Secure Gateway (ISG).

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Go to "Network and Adapters".
3. Scroll down to the "Bridge" section, if a bridge is not configured, this is a finding.

If a bridge is configured but the two network interfaces on the ISG are not added, this is a finding.

Vulnerability Number

V-279219

Documentable

False

Rule Version

SYME-00-009800

Severity Override Guidance

Implementation of multiple Edge SWG nodes must be done in a transparent proxy using an ethernet bridge. This is done using the Symantec Integrates Secure Gateway (ISG).

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Go to "Network and Adapters".
3. Scroll down to the "Bridge" section, if a bridge is not configured, this is a finding.

If a bridge is configured but the two network interfaces on the ISG are not added, this is a finding.

Check Content Reference

M

Target Key

5725