STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Firewall Security Requirements Guide

V-206700

CAT II (Medium)

If communication with the central audit server is lost, the firewall must generate a real-time alert to, at a minimum, the systems adminsitrator (SA) and information system security officer (ISSO).

Rule ID

SV-206700r1140705_rule

STIG

Firewall Security Requirements Guide

Version

V3R3

CCIs

CCI-001858

Discussion

Without a real-time alert (less than a second), security personnel may be unaware of an impending failure of the audit functions and system operation may be adversely impacted. Alerts provide organizations with urgent messages. Automated alerts can be conveyed in a variety of ways, including via a regularly monitored console, telephonically, via electronic mail, via text message, or via websites. Log processing failures include software/hardware errors, failures in the log capturing mechanisms, and log storage capacity being reached or exceeded. Most firewalls use UDP to send audit records to the server and cannot tell if the server has received the transmission, thus the site should either implement a connection-oriented communications solution (e.g., TCP) or implement a heartbeat with the central audit server and send an alert if it is unreachable.

Check Content

If a network device such as the events, network management, or SNMP server is configured to send an alert when communication is lost with the central audit server, this is not a finding.

Verify the firewall is configured to send an alert via instant message, email, SNMP, or another authorized method to the SA, ISSO, and other identified personnel when communication is lost with the central audit server.

If the firewall is not configured to send an immediate alert via an approved method when communication is lost with the central audit server, this is a finding.

Fix Text

Configure the firewall (or another network device) to send an alert via instant message, email, or another authorized method to the SA, ISSO, and other identified personnel for any log failure event where the filtering functions are unable to write events to the central audit server.