SV-279250r1170680_rule
V-279250
SRG-APP-000033-NDM-000212
SYME-ND-000170
CAT I
10
1. In the Edge SWG Web UI, navigate to the VPM.
2. Click "Add Layer".
3. Scroll down and select "Admin Access", then click "Add".
4. Locate the Admin Access Layer (1) layer that was added and click "Add rule".
5. Inside of the rule, under "Source", left-click and select "Set".
6. Click "Add new Object".
7. Select "Group".
8. Under the group field, type in the full LDAPS Distinguished Name (DN) for the admin group. For example: "CN=roadcom.admins.gsg,OU=BROADCOM,OU=Vendors, DC=dod,DC=local"
9. Under the "Authentication Realm", select the "CAC certificate" realm.
10. Click "Apply", then click "Set".
11. In the same rule, left-click in the "Service" field and click "Set".
12. Select "Service Name: HTTPS-console" and click "Set".
13. In the same rule, left-click in the "Action" field and click "Set".
14. Select the action "Allow Read/Write Access" and click "Set".
15. Repeat these steps to add various read-only or read-write groups for the HTTPS-console.
16. For the SSH-Console click "Add rule".
17. Inside of the rule, under "Source", left-click and select "Set".
18. Click "Add new Object".
19. Select "Group".
20. Under the "Group" field, type in the full LDAPS Distinguished Name (DN) for the admin group. For example: CN=broadcom.admins.gsg,OU=BROADCOM,OU=Vendors, DC=dod,DC=local
21. Under the "Authentication Realm", select the "LDAPS" realm. Do not select the CAC certificate realm.
22. Click "Apply", then click "Set".
23. In the same rule, left-click in the "Service" field and click "Set".
24. Select "Service Name: SSH-console", and then click "Set".
25. In the same rule, left-click in the "Action" field and click "Set".
26. Select the action "Allow Read/Write Access" and click "Set".
27. Repeat these steps to add various read-only or read-write groups for the SSH-console.
In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).
Under the layers, if an "Admin Access" layer is not configured, this is a finding.
If an "Admin Access" layer is configured, for HTTPS-console, verify the group is derived from the CAC/LDAPS admin group; otherwise, this is a finding.
For the SSH-console, verify the group is derived from the LDAPS admin group; otherwise, this is a finding.
V-279250
False
SYME-ND-000170
In the Edge SWG Web UI, navigate to the Visual Policy Manager (VPM).
Under the layers, if an "Admin Access" layer is not configured, this is a finding.
If an "Admin Access" layer is configured, for HTTPS-console, verify the group is derived from the CAC/LDAPS admin group; otherwise, this is a finding.
For the SSH-console, verify the group is derived from the LDAPS admin group; otherwise, this is a finding.
M
5726