Check: TIDX-BK-000002
Trellix TIE/DXL STIG:
TIDX-BK-000002
(in versions v2 r2 through v1 r0.1)
Title
The McAfee Data Exchange Layer (DXL) Broker Management Client Connection Limit must be configured to 50,000 users or less. (Cat II impact)
Discussion
Application management includes the ability to control the number of users and user sessions that utilize an application. Limiting the number of allowed users and sessions per user is helpful in limiting risks related to DoS attacks. This requirement may be met via the application or by utilizing information system session control provided by a web server with specialized session management capabilities. If it has been specified that this requirement will be handled by the application, the capability to limit the maximum number of concurrent single user sessions must be designed and built into the application. This requirement addresses concurrent sessions for information system accounts and does not address concurrent sessions by single users via multiple system accounts. The maximum number of concurrent sessions should be defined based upon mission needs and the operational environment for each system. The McAfee DXL Client Connection Limit sets the number of clients that can be connected to broker that uses the policy. Default is 50,000.
Check Content
This check needs to be completed for the active McAfee TIE Server Management policy that manages the site McAfee TIE. From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee DXL Broker Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Verify the Client Connection Limit is set to 50,000 or less. If the Client Connection Limit is not set to 50,000 or less, this is a finding.
Fix Text
From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee DXL Broker Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Set the Client Connection Limit to 50,000 or less.
Additional Identifiers
Rule ID: SV-221990r506938_rule
Vulnerability ID: V-221990
Group Title: SRG-APP-000001
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000054 |
Limit the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number. |
Controls
Number | Title |
---|---|
AC-10 |
Concurrent Session Control |