STIGQter STIGQter: STIG Summary: Symantec Edge SWG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

The Edge SWG must be configured to assign appropriate user roles or access levels to authenticated users.

DISA Rule

SV-279250r1170680_rule

Vulnerability Number

V-279250

Group Title

SRG-APP-000033-NDM-000212

Rule Version

SYME-ND-000170

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the VPM.
2. Click "Add Layer".
3. Scroll down and select "Admin Access", then click "Add".
4. Locate the Admin Access Layer (1) layer that was added and click "Add rule".
5. Inside of the rule, under "Source", left-click and select "Set".
6. Click "Add new Object".
7. Select "Group".
8. Under the group field, type in the full LDAPS Distinguished Name (DN) for the admin group. For example: "CN=roadcom.admins.gsg,OU=BROADCOM,OU=Vendors, DC=dod,DC=local"
9. Under the "Authentication Realm", select the "CAC certificate" realm.
10. Click "Apply", then click "Set".
11. In the same rule, left-click in the "Service" field and click "Set".
12. Select "Service Name: HTTPS-console" and click "Set".
13. In the same rule, left-click in the "Action" field and click "Set".
14. Select the action "Allow Read/Write Access" and click "Set".
15. Repeat these steps to add various read-only or read-write groups for the HTTPS-console.
16. For the SSH-Console click "Add rule".
17. Inside of the rule, under "Source", left-click and select "Set".
18. Click "Add new Object".
19. Select "Group".
20. Under the "Group" field, type in the full LDAPS Distinguished Name (DN) for the admin group. For example: CN=broadcom.admins.gsg,OU=BROADCOM,OU=Vendors, DC=dod,DC=local
21. Under the "Authentication Realm", select the "LDAPS" realm. Do not select the CAC certificate realm.
22. Click "Apply", then click "Set".
23. In the same rule, left-click in the "Service" field and click "Set".
24. Select "Service Name: SSH-console", and then click "Set".
25. In the same rule, left-click in the "Action" field and click "Set".
26. Select the action "Allow Read/Write Access" and click "Set".
27. Repeat these steps to add various read-only or read-write groups for the SSH-console.

Check Contents

In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).

Under the layers, if an "Admin Access" layer is not configured, this is a finding.

If an "Admin Access" layer is configured, for HTTPS-console, verify the group is derived from the CAC/LDAPS admin group; otherwise, this is a finding.

For the SSH-console, verify the group is derived from the LDAPS admin group; otherwise, this is a finding.

Vulnerability Number

V-279250

Documentable

False

Rule Version

SYME-ND-000170

Severity Override Guidance

In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).

Under the layers, if an "Admin Access" layer is not configured, this is a finding.

If an "Admin Access" layer is configured, for HTTPS-console, verify the group is derived from the CAC/LDAPS admin group; otherwise, this is a finding.

For the SSH-console, verify the group is derived from the LDAPS admin group; otherwise, this is a finding.

Check Content Reference

M

Target Key

5726