Check: SYMP-AG-000530
Symantec ProxySG ALG STIG:
SYMP-AG-000530
(in versions v1 r3 through v1 r1)
Title
Symantec ProxySG must implement load balancing to limit the effects of known and unknown types of denial-of-service (DoS) attacks. (Cat II impact)
Discussion
If the network does not provide safeguards against DoS attacks, network resources will be unavailable to users. Load balancing provides service redundancy, which reduces the susceptibility of the ALG to many DoS attacks. The ALG must be configured to prevent or mitigate the impact on network availability and traffic flow of DoS attacks that have occurred or are ongoing. This requirement applies to the network traffic functionality of the device as it pertains to handling network traffic. Some types of attacks may be specialized to certain network technologies, functions, or services. For each technology, known and potential DoS attacks must be identified and solutions for each type implemented. For detailed information, see the ProxySG Administration Guide, Chapter 39: Configuring Failover.
Check Content
Verify that redundancy has been configured on the ProxySG. 1. Log on to the Web Management Console. 2. Browse to Configuration >> Network >> Advanced. 3. Select the "Failover" tab and Verify that entries are present and that they are "enabled". If Symantec ProxySG does not implement load balancing to limit the effects of known and unknown types of DoS attacks, this is a finding.
Fix Text
Configure redundancy on the ProxySG. 1. Log on to the Web Management Console. 2. Browse to Configuration >> Network >> Advanced. 3. Select the "Failover" tab and configure using the SSP requirements.
Additional Identifiers
Rule ID: SV-104273r1_rule
Vulnerability ID: V-94319
Group Title: SRG-NET-000362-ALG-000120
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002385 |
The information system protects against or limits the effects of organization-defined types of denial of service attacks by employing organization-defined security safeguards. |
Controls
Number | Title |
---|---|
SC-5 |
Denial Of Service Protection |