Skip to main content

September 4, 2026

Security settings

This section covers the security settings configured for Unified Access Gateway.

SSH

By default, root console access to Unified Access Gateway using the SSH protocol is deactivated. You can activate SSH access using the password access or the SSH keys or both. If required, it can be limited to access on individual NICs.

By restricting SSH access to specific NICs, it is also possible to use a jumpbox and ensure limited access to that jumpbox.

Compliance

Security Technical Implementation Guides (STIGs)

Unified Access Gateway supports configuration settings to allow Unified Access Gateway to comply with the AlmaLinux 9 DISA STIG. For this compliance, the FIPS version of Unified Access Gateway must be used and specific configuration settings are applied at deploy time.

NIAP CSfC Guidelines for Unified Access Gateway when used with Horizon

The US National Security Agency (NSA) has developed, approved, and published solution-level specifications called Capability Packages (CPs). In addition to the CPs, the National Security Agency, and the National Information Assurance Partnership (NIAP) works with technical communities from across industries, governments, and academia to develop, maintain, and publish product-level security requirements called Protection Profiles (PPs).

NSA/CSS's (Central Security Service) Commercial Solutions for Classified (CSfC) Program is established to allow commercial products to be used in layered solutions protecting classified National Security Systems (NSS) data.

Unified Access Gateway with Horizon is NIAP/CSfC compliant and uses the CSfC Selections for Transport Layer Security (TLS) Protected Servers. This validation requires specific configuration in the Unified Access Gateway appliance which is necessary for the NIAP/CSfC operation.

FedRAMP Compliance

The Federal Risk and Management Program (FedRAMP) is a cyber security risk management program for the use of cloud products and services used by U.S. federal agencies. FedRAMP uses the National Institute of Standards and Technology’s (NIST) guidelines and procedures to provide standardized security requirements for cloud services. Specifically, FedRAMP leverages NIST’s Special Publication [SP] 800-53 - Security and Privacy Controls for Federal Information Systems and Organizations series, the baselines and test cases.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…