STIGQter STIGQter: STIG Summary: Cisco NX OS Switch NDM Security Technical Implementation Guide Version: 3 Release: 6 Benchmark Date: 05 Jan 2026:

The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.

DISA Rule

SV-220504r1026075_rule

Vulnerability Number

V-220504

Group Title

SRG-APP-000412-NDM-000331

Rule Version

CISC-ND-001210

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the Cisco router to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm as shown in the examples below.

SSH Example

R1(config)#ssh ciphers aes128-ctr aes256-ctr

Check Contents

Review the Cisco router configuration to verify it is compliant with this requirement.

SSH Example

ssh ciphers aes128-ctr aes256-ctr

NOTE: Using "fips mode enable" to enable all FIPS protocols disables TACACS+ and RADIUS, which is required for authentication server requirements. It is recommended to enable FIPS-validated protocols manually and keep FIPS mode disabled.

If the router is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm, this is a finding.

Vulnerability Number

V-220504

Documentable

False

Rule Version

CISC-ND-001210

Severity Override Guidance

Review the Cisco router configuration to verify it is compliant with this requirement.

SSH Example

ssh ciphers aes128-ctr aes256-ctr

NOTE: Using "fips mode enable" to enable all FIPS protocols disables TACACS+ and RADIUS, which is required for authentication server requirements. It is recommended to enable FIPS-validated protocols manually and keep FIPS mode disabled.

If the router is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm, this is a finding.

Check Content Reference

M

Target Key

4066