STIGQter STIGQter: STIG Summary: Symantec Edge SWG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

The Edge SWG must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).

DISA Rule

SV-279268r1170603_rule

Vulnerability Number

V-279268

Group Title

SRG-APP-000395-NDM-000310

Rule Version

SYME-ND-000710

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Select the "SNMP" and "SNMP" areas.
3. Under "V3 Users", click "Add User".
4. Enter the username.
5. Select "SHA" for authentication and type a passphrase.
6. Select AES and type a passphrase.
7. Under "V3 Traps and Informs", add a trap destination if applicable.

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Select the "Services" and "Management Services" areas.
3. Enable SNMP, add the listener for both IPv4 and IPv6.

1. In the Edge SWG Web UI, navigate to the Visual Policy Manager.
Note: Ensure the Admin Access Layer was created before moving on to this step.
2. Under the "Admin Access Layer", click "Add Rule".
3. Under "Source", select "Any".
4. Under "Service", select "Service Name: SNMP".
5. Under "Action", select "Allow Read-only Access".
6. Apply the policy.

Check Contents

1. Log in to the Edge SWG SSH CLI.
2. Enter "show snmp".

If the line for SNMPv1 and SNMPv2c does not say "disabled", this is a finding.

Below is an example of what the line will look in a correct state:
"SNMPv1 is disabled. SNMPv2c is disabled."

Vulnerability Number

V-279268

Documentable

False

Rule Version

SYME-ND-000710

Severity Override Guidance

1. Log in to the Edge SWG SSH CLI.
2. Enter "show snmp".

If the line for SNMPv1 and SNMPv2c does not say "disabled", this is a finding.

Below is an example of what the line will look in a correct state:
"SNMPv1 is disabled. SNMPv2c is disabled."

Check Content Reference

M

Target Key

5726