Check: SYMP-AG-000320
Symantec ProxySG ALG STIG:
SYMP-AG-000320
(in versions v1 r3 through v1 r1)
Title
Symantec ProxySG must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). (Cat I impact)
Discussion
To assure accountability and prevent unauthenticated access, organizational users must be identified and authenticated to prevent potential misuse and compromise of the system. Organizational users include organizational employees or individuals the organization deems to have equivalent status of employees (e.g., contractors). Organizational users (and any processes acting on behalf of users) must be uniquely identified and authenticated for all accesses except the following. By default, the ProxySG operates as an un-authenticated proxy. Authentication of users must be explicitly configured as described here and in in the ProxySG Administration Guide, Chapter 49: Controlling Access to the Internet and Intranet.
Check Content
Verify that ProxySG is uniquely identifying organizational users. 1. Log on to the Web Management Console. 2. Browse to Configuration >> Authentication >> Windows Domain. 3. Verify that a domain is listed in the Domains field and indicates "Joined and Used". If Symantec ProxySG does not uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users), this is a finding.
Fix Text
Configure the ProxySG to perform unique identification of organizational users. 1. Log on to the Web Management Console. 2. Browse to Configuration >> Authentication >> Windows Domain. 3. Click "Add New Domain" and follow prompts to join the Windows Domain.
Additional Identifiers
Rule ID: SV-104233r1_rule
Vulnerability ID: V-94279
Group Title: SRG-NET-000138-ALG-000063
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. |
Controls
Number | Title |
---|---|
IA-2 |
Identification and Authentication (organizational Users) |