SV-246949r961506_rule
V-246949
SRG-APP-000395-NDM-000310
NAOT-IA-000003
CAT II
10
Configure a snmpV3 user using FIPS-validated Keyed-HMAC with "security login create -user-or-group-name snmptest2 -application snmp -authentication-method usm".
Enter the authoritative entity's EngineID [local EngineID]:
Which authentication protocol do you want to choose (none, md5, sha, sha2-256) [none]: sha2-256
Enter the authentication protocol password (minimum 8 characters long):
Enter the authentication protocol password again:
Which privacy protocol do you want to choose (none, des, aes128) [none]: aes128.
Validate that SNMP is enabled using the command "options -option-name snmp*".
If snmp.enable and snmp.san.enable are set to "off", then SNMP is not enabled and this requirement is not applicable.
Use "security snmpusers -authmethod usm" to see snmpV3 users using FIPS-validated Keyed-HMAC.
If ONTAP is not configured to authenticate SNMP messages using FIPS-validated Keyed-HMAC, this is a finding.
V-246949
False
NAOT-IA-000003
Validate that SNMP is enabled using the command "options -option-name snmp*".
If snmp.enable and snmp.san.enable are set to "off", then SNMP is not enabled and this requirement is not applicable.
Use "security snmpusers -authmethod usm" to see snmpV3 users using FIPS-validated Keyed-HMAC.
If ONTAP is not configured to authenticate SNMP messages using FIPS-validated Keyed-HMAC, this is a finding.
M
5415