SV-220504r1026075_rule
V-220504
SRG-APP-000412-NDM-000331
CISC-ND-001210
CAT I
10
Configure the Cisco router to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm as shown in the examples below.
SSH Example
R1(config)#ssh ciphers aes128-ctr aes256-ctr
Review the Cisco router configuration to verify it is compliant with this requirement.
SSH Example
ssh ciphers aes128-ctr aes256-ctr
NOTE: Using "fips mode enable" to enable all FIPS protocols disables TACACS+ and RADIUS, which is required for authentication server requirements. It is recommended to enable FIPS-validated protocols manually and keep FIPS mode disabled.
If the router is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm, this is a finding.
V-220504
False
CISC-ND-001210
Review the Cisco router configuration to verify it is compliant with this requirement.
SSH Example
ssh ciphers aes128-ctr aes256-ctr
NOTE: Using "fips mode enable" to enable all FIPS protocols disables TACACS+ and RADIUS, which is required for authentication server requirements. It is recommended to enable FIPS-validated protocols manually and keep FIPS mode disabled.
If the router is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm, this is a finding.
M
4066