STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).

DISA Rule

SV-251000r1028238_rule

Vulnerability Number

V-251000

Group Title

SRG-APP-000395-NDM-000310

Rule Version

MOIS-ND-000760

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

On Sentry console, do the following to configure FIPS mode:

1. SSH to the Sentry.
2. At the prompt, enter "enable" mode with the secret credentials.
3. Type Configure command.
4. Type FIPS.
5. Once reloaded, SSH to the Sentry.
6. Run the "show FIPS".

Then:
1. Log in to Sentry.
2. Go to Settings >> SNMP.
3. Add SNMP Trap Receiver.
4. Enable SNMP Service.
5. Select Protocol v3.
6. Add SNMP v3 Users.
7. Enter User Name.
8. Select Security Level from dropdown.
9. Select AUTH Protocol from dropdown.
10. Enter AUTH Password.
11. Select Privacy Protocol from dropdown.
12. Enter Privacy Password.
13. Click "Save".
14. Enable Link Up/Down Trap.
15. Click "Apply" to save changes.

Check Contents

On the Sentry console, do the following to verify FIPS mode is enabled:

1. SSH to Sentry Server from any SSH client.
2. Enter the administrator credentials set at Sentry installation.
3. Enter "enable".
4. When prompted, enter the "enable secret" set at Sentry installation.
5. Enter "show FIPS".
6. Verify "FIPS 140 mode is enabled" is displayed. If it is not, this is a finding.

Then:
1. Log in to Sentry.

2. Go to Settings >> SNMP.

3. Verify SNMP server has been added.
a. If SNMP server is not added, this is a finding.
b. If SNMP server is added, go to step 4.

4. Verify SNMP Control is not disabled.
a. If SNMP Control is disabled, this is a finding.
b. If SNMP Control is not disabled, go to step 5.

5. Verify Protocol v3 is selected.
a. If Protocol v3 is not selected, this is a finding.
b. If Protocol v3 is selected, go to step 6.

6. Verify the SNMP v3 User has been added.
a. If SNMP v3 User has not been added, this is a finding.

Vulnerability Number

V-251000

Documentable

False

Rule Version

MOIS-ND-000760

Severity Override Guidance

On the Sentry console, do the following to verify FIPS mode is enabled:

1. SSH to Sentry Server from any SSH client.
2. Enter the administrator credentials set at Sentry installation.
3. Enter "enable".
4. When prompted, enter the "enable secret" set at Sentry installation.
5. Enter "show FIPS".
6. Verify "FIPS 140 mode is enabled" is displayed. If it is not, this is a finding.

Then:
1. Log in to Sentry.

2. Go to Settings >> SNMP.

3. Verify SNMP server has been added.
a. If SNMP server is not added, this is a finding.
b. If SNMP server is added, go to step 4.

4. Verify SNMP Control is not disabled.
a. If SNMP Control is disabled, this is a finding.
b. If SNMP Control is not disabled, go to step 5.

5. Verify Protocol v3 is selected.
a. If Protocol v3 is not selected, this is a finding.
b. If Protocol v3 is selected, go to step 6.

6. Verify the SNMP v3 User has been added.
a. If SNMP v3 User has not been added, this is a finding.

Check Content Reference

M

Target Key

5438