STIGQter STIGQter: STIG Summary: Symantec Edge SWG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Apr 2026:

The Edge SWG must authenticate Network Time Protocol sources using authentication that is cryptographically based.

DISA Rule

SV-279269r1170698_rule

Vulnerability Number

V-279269

Group Title

SRG-APP-000395-NDM-000347

Rule Version

SYME-ND-000720

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Log in to the Edge SWG SSH CLI.
2. Enter "enable" and "configure terminal".
3. Enter "ntp enable".
4. Enter "ntp server <NTP SERVER IP/HOSTNAME> <KEY ID> sha1".
Note: The key ID must be a number and match the NTP server.
5. When prompted with "key:", enter the hexadecimal SHA preshared key.
6. Repeat these steps for the site's second NTP server.

Check Contents

1. Log in to the Edge SWG SSH CLI.
2. Enter "enable" and "configure terminal".
3. Enter "show ntp".

If NTP is not enabled, this is a finding.

If there are not two NTP servers in use, this is a finding.

If the two NTP servers are not using SHA1 preshared keys for authentication, this is a finding.

Vulnerability Number

V-279269

Documentable

False

Rule Version

SYME-ND-000720

Severity Override Guidance

1. Log in to the Edge SWG SSH CLI.
2. Enter "enable" and "configure terminal".
3. Enter "show ntp".

If NTP is not enabled, this is a finding.

If there are not two NTP servers in use, this is a finding.

If the two NTP servers are not using SHA1 preshared keys for authentication, this is a finding.

Check Content Reference

M

Target Key

5726