You can enable Common Criteria (CC) mode in Intelligent Sandbox. On enabling the CC mode, you might see various security warnings which you can either accept or fix the security warning by reviewing the Security Logs.
From the Syslog settings page:
Enable logging.
Choose TCP/TLS in communication protocol
Enable Validate Syslog Server Certificate.
Note
In Common Criteria (CC) mode:
The minimum TLS version is set to 1.2.
FTP Access, HTTP, and SSH access are disabled.
Due to the SSH being disabled, Intelligent Sandbox cluster is not available in CC mode.
Intelligent Sandbox uses only SSL connections with NSP.
Web server and Syslog server certificates are strictly validated. Ensure the following:
Root CA certificate for Web server and syslog server is uploaded in Trusted CA certificate. The root CA should be trusted by Intelligent Sandbox for any communication with syslog server and web server, else the communication fails.
Certificate validation checks for valid certificate validity, key length, signature algorithm, chain validation, extended purpose, and revocation.
Syslog server, Web server, and all intermediate certificates must have either OCSP or CRL (only HTTP URL is supported) information included, else the chain validation fails.
Syslog server, Web server, and all intermediate certificate have Authority Information Access extension information of issuer CA (only HTTP URL is supported).
Log on to the Intelligent Sandbox web interface.
Click → → , then select Enable Logging.
Configure the System Log Server options, then click Test connection to test the connection.
In the Statistics to Log area, make sure Audit Log is checked. By default Audit Log is enabled.
Click Submit.
Go to → → , select Common Criteria Mode.
Audit function starts as Intelligent Sandbox boots up and stops with Intelligent Sandbox shutdown. The function restarts in the following two scenarios.
Change in Syslog certificate.
Manual change in the Date and Time information.