SV-279272r1172804_rule
V-279272
SRG-APP-000516-NDM-000340
SYME-ND-000780
CAT II
10
1. Log in to the Edge SWG SSH CLI.
2. Enter "enable" and "configure terminal".
3. Enter "archive-configuration archive-signing enforce-signed enable".
4. Enter "archive-configuration automatic-upload".
5. Enter "archive-configuration host" and add the IP address or hostname of the site's SCP backup server.
6. Enter "archive-configuration username" and add the username of the site's SCP backup server.
7. Enter "archive-configuration password" and add the site's password of the site's SCP backup server.
8. Enter "archive-configuration path" and add the site's backup server path (e.g., /home/tachyon-ftp/files/broadcom/).
9. Enter "archive-configuration filename-prefix SG_%l_%Y%m%d%H%M".
10. Enter "archive-configuration periodic-upload minutes 10080".
11. Enter "archive-configuration protocol scp".
12. Enter "archive-configuration scp-authentication password".
13. Enter "archive-configuration ssl-device-profile" and add the "SSL Device Profile" in use for the HTTPS-console and x509 authentication.
1. Log in to the Edge SWG SSH CLI.
2. Enter "show archive-configuration".
If no server is configured, this is a finding.
If "Automatic upload" is not set to "Enabled", this is a finding.
If "Upload interval" is not set for "every 10080 minutes", this is a finding.
V-279272
False
SYME-ND-000780
1. Log in to the Edge SWG SSH CLI.
2. Enter "show archive-configuration".
If no server is configured, this is a finding.
If "Automatic upload" is not set to "Enabled", this is a finding.
If "Upload interval" is not set for "every 10080 minutes", this is a finding.
M
5726