STIGQter STIGQter: STIG Summary: NetApp ONTAP DSC 9.x Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

ONTAP must be configured to authenticate SNMP messages using FIPS-validated Keyed-HMAC.

DISA Rule

SV-246949r961506_rule

Vulnerability Number

V-246949

Group Title

SRG-APP-000395-NDM-000310

Rule Version

NAOT-IA-000003

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure a snmpV3 user using FIPS-validated Keyed-HMAC with "security login create -user-or-group-name snmptest2 -application snmp -authentication-method usm".

Enter the authoritative entity's EngineID [local EngineID]:

Which authentication protocol do you want to choose (none, md5, sha, sha2-256) [none]: sha2-256

Enter the authentication protocol password (minimum 8 characters long):

Enter the authentication protocol password again:

Which privacy protocol do you want to choose (none, des, aes128) [none]: aes128.

Check Contents

Validate that SNMP is enabled using the command "options -option-name snmp*".

If snmp.enable and snmp.san.enable are set to "off", then SNMP is not enabled and this requirement is not applicable.

Use "security snmpusers -authmethod usm" to see snmpV3 users using FIPS-validated Keyed-HMAC.

If ONTAP is not configured to authenticate SNMP messages using FIPS-validated Keyed-HMAC, this is a finding.

Vulnerability Number

V-246949

Documentable

False

Rule Version

NAOT-IA-000003

Severity Override Guidance

Validate that SNMP is enabled using the command "options -option-name snmp*".

If snmp.enable and snmp.san.enable are set to "off", then SNMP is not enabled and this requirement is not applicable.

Use "security snmpusers -authmethod usm" to see snmpV3 users using FIPS-validated Keyed-HMAC.

If ONTAP is not configured to authenticate SNMP messages using FIPS-validated Keyed-HMAC, this is a finding.

Check Content Reference

M

Target Key

5415