Skip to content

A10 Networks ADC ALG Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000383-ALG-000135

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC, when used to load balance web applications, must enable external logging for WAF data event messages.

    &lt;VulnDiscussion&gt;Without coordinated reporting between separate devices, it is not possible to identify the true scale and possible target of ...
    Rule Low Severity
  • SRG-NET-000392-ALG-000141

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must enable logging for packet anomaly events.

    &lt;VulnDiscussion&gt;Without an alert, security personnel may be unaware of major detection incidents that require immediate action and this delay...
    Rule Medium Severity
  • SRG-NET-000392-ALG-000142

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must generate an alert to, at a minimum, the ISSO and ISSM when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected.

    &lt;VulnDiscussion&gt;Without an alert, security personnel may be unaware of major detection incidents that require immediate action and this delay...
    Rule Medium Severity
  • SRG-NET-000392-ALG-000148

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must enable logging of Denial of Service (DoS) attacks.

    &lt;VulnDiscussion&gt;Without an alert, security personnel may be unaware of major detection incidents that require immediate action, and this dela...
    Rule Medium Severity
  • SRG-NET-000401-ALG-000127

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC, when used for load-balancing web servers, must not allow the HTTP TRACE and OPTIONS methods.

    &lt;VulnDiscussion&gt;HTTP offers a number of methods that can be used to perform actions on the web server. Some of these HTTP methods can be used...
    Rule Medium Severity
  • SRG-NET-000402-ALG-000130

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must reveal error messages only to authorized individuals (ISSO, ISSM, and SA).

    &lt;VulnDiscussion&gt;Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an orga...
    Rule Medium Severity
  • SRG-NET-000511-ALG-000051

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must, at a minimum, off-load audit log records onto a centralized log server.

    &lt;VulnDiscussion&gt;Off-loading ensures audit information does not get overwritten if the limited audit storage capacity is reached and also prot...
    Rule Low Severity
  • SRG-NET-000512-ALG-000062

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC, when used for load balancing web servers, must deploy the WAF in active mode.

    &lt;VulnDiscussion&gt;The Web Application Firewall (WAF) supports three operational modes - Learning, Passive, and Active. Active is the standard o...
    Rule Medium Severity
  • SRG-NET-000512-ALG-000062

    <GroupDescription></GroupDescription>
    Group
  • If the Data Owner requires it, the A10 Networks ADC must be configured to perform CCN Mask, SSN Mask, and PCRE Mask Request checks.

    &lt;VulnDiscussion&gt;If outbound communications traffic is not continuously monitored, hostile activity may not be detected and prevented. Output ...
    Rule Medium Severity
  • SRG-NET-000362-ALG-000112

    <GroupDescription></GroupDescription>
    Group
  • The A10 Networks ADC must protect against ICMP-based Denial of Service (DoS) attacks by employing ICMP Rate Limiting.

    &lt;VulnDiscussion&gt;If the network does not provide safeguards against DoS attacks, network resources will be unavailable to users. Installation ...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules