UCF STIG Viewer Logo

The ICS must be configured to send user traffic log data to redundant central log server.


Overview

Finding ID Version Rule ID IA Controls Severity
V-258592 IVCS-VN-000305 SV-258592r930464_rule Medium
Description
The aggregation of log data kept on a syslog server can be used to detect attacks and trigger an alert to the appropriate security personnel. The stored log data can used to detect weaknesses in security that enable the network IA team to find and address these weaknesses before breaches can occur. Reviewing these logs, whether before or after a security breach, are important in showing whether someone is an internal employee or an outside threat. This requirement applies only to components where this is specific to the function of the device (e.g., IDPS sensor logs, firewall logs). This does not apply to audit logs generated on behalf of the device itself (management).
STIG Date
Ivanti Connect Secure VPN Security Technical Implementation Guide 2023-10-17

Details

Check Text ( C-62332r930462_chk )
Verify user access log events are being sent to the central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings.
1. Under "Select Events to Log", verify all items are checked.
2. Under "Syslog Servers", verify redundant server name/IP address, facility of LOCAL0, type TLS, and the source interface are defined.

If the ICS must be configured to send admin log data to redundant central log server, this is a finding.
Fix Text (F-62241r930463_fix)
Direct user access log events to the central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> User Access >> Settings.
1. Under "Select Events to Log", check all items.
2. Under "Syslog Servers", add an IP address/server name/IP.
3. Set the facility to "LOCAL0".
4. Set type to "TLS".
5. If a client cert is required for the syslog server, select the client certificate to use for the syslog traffic. If none exists, import the DOD-signed client key pair to the ICS under System >> Configuration >> Certificates >> Client Auth Certificates.
6. Set the standard filer.
7. Set the source interface as either the management or internal interface.
8. Click "Add".
9. Click "Save Changes".
10. Repeat these steps to add a redundant syslog server for user log events.