STIGQter STIGQter: STIG Summary: CA API Gateway ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 28 Apr 2017:

The CA API Gateway must implement load balancing to limit the effects of known and unknown types of Denial of Service (DoS) attacks.

DISA Rule

SV-86069r1_rule

Vulnerability Number

V-71445

Group Title

SRG-NET-000362-ALG-000120

Rule Version

CAGW-GW-000680

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the CA API Gateway - Policy Manager and double-click all Registered Services requiring load balancing.

Verify/add a "Route via HTTP(s)" Assertion within the policy and double-click it.

Click the "Connection" button and chose either the "Use the following IP addresses:" or "Use multiple URLs:" radio button.

Configure multiple IP addresses/URLs and set the Failover strategy in accordance with organizational requirements.

Check Contents

Open the CA API Gateway - Policy Manager and double-click all Registered Services requiring load balancing.

Verify there is a "Route via HTTP(S)" Assertion included in the policy and double-click it.

Click the "Connection" button and verify either the "Use the following IP addresses:" or "Use multiple URLs:" radio button is selected and that multiple URLs/IP addresses are listed in the box.

If the assertion is not included within the policies or multiple URLs/IP addresses are not being used, this is a finding.

Vulnerability Number

V-71445

Documentable

False

Rule Version

CAGW-GW-000680

Severity Override Guidance

Open the CA API Gateway - Policy Manager and double-click all Registered Services requiring load balancing.

Verify there is a "Route via HTTP(S)" Assertion included in the policy and double-click it.

Click the "Connection" button and verify either the "Use the following IP addresses:" or "Use multiple URLs:" radio button is selected and that multiple URLs/IP addresses are listed in the box.

If the assertion is not included within the policies or multiple URLs/IP addresses are not being used, this is a finding.

Check Content Reference

M

Target Key

3049

Comments