More than one Edge server must be deployed.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-259596 | SRG-APP-000246 | EX19-ED-000109 | SV-259596r961152_rule | 2024-12-06 | 2 |
| Description |
|---|
| To ensure hostile insiders are unable to easily commit DoS attacks and reduce the effectiveness of mail flow throughout the environment, a second Edge server is deployed to allow for multiple paths of mail flow both internally and externally into the environment. This prevents a single point-of-failure and allows for service to continue in the event of a DoS attack targeting one Edge role. |
| ℹ️ Check |
|---|
| Review the EDSP for current configuration. On the mailbox server, open a PowerShell prompt and run the following command: Get-EdgeSubscription If there is only one subscription on each server, this is a finding. |
| ✔️ Fix |
|---|
| At a minimum, a second server must be deployed and subscribed to. |