SV-253929r1167984_rule
V-253929
SRG-APP-000412-NDM-000331
JUEX-NM-000520
CAT I
10
Configure the network device to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2/FIPS 140-3 approved algorithm.
set snmp v3 usm local-engine user <SNMPv3 user> authentication-sha authentication-password "PSK"
set snmp v3 usm local-engine user <SNMPv3 user> privacy-aes128 privacy-password "PSK"
Note: Use the strongest HMAC mutually supported with the NMS (e.g., authentication-sha256, authentication-sha512)
set system services ssh protocol-version v2
set system services ssh ciphers aes256-ctr
set system services ssh macs hmac-sha2-512
set system services ssh macs hmac-sha2-256
set system services ssh key-exchange ecdh-sha2-nistp521
set system services ssh key-exchange ecdh-sha2-nistp384
set system services ssh key-exchange ecdh-sha2-nistp256
Review the network device configuration to determine if cryptographic mechanisms are implemented using a FIPS 140-2/FIPS 140-3 approved algorithm to protect the confidentiality of remote maintenance sessions.
If using SNMPv3, verify (minimally) that authentication-sha is configured. Juniper devices also support authentication-sha224/256/384/512. Verify the strongest mutually supported HMAC between the network device and the Network Management Server (NMS) is configured.
[edit system snmp]
v3 {
usm {
local-engine {
user <SNMPv3 user> {
authentication-sha {
authentication-key "PSK"; ## SECRET-DATA
}
}
}
}
}
Verify SSHv2 is configured for protocol V2 only, ciphers [ aes256-ctr ], key-exchange [ ecdh-sha2-nistp521 ecdh-sha2-nistp384 ecdh-sha2-nistp256 ], and macs [ hmac-sha2-512 hmac-sha2-256 ].
[edit system services ssh]
:
protocol-version v2;
ciphers [ aes256-ctr];
macs [ hmac-sha2-512 hmac-sha2-256 ];
key-exchange [ ecdh-sha2-nistp521 ecdh-sha2-nistp384 ecdh-sha2-nistp256 ];
If the network device is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2/FIPS 140-3 approved algorithm, this is a finding.
V-253929
False
JUEX-NM-000520
Review the network device configuration to determine if cryptographic mechanisms are implemented using a FIPS 140-2/FIPS 140-3 approved algorithm to protect the confidentiality of remote maintenance sessions.
If using SNMPv3, verify (minimally) that authentication-sha is configured. Juniper devices also support authentication-sha224/256/384/512. Verify the strongest mutually supported HMAC between the network device and the Network Management Server (NMS) is configured.
[edit system snmp]
v3 {
usm {
local-engine {
user <SNMPv3 user> {
authentication-sha {
authentication-key "PSK"; ## SECRET-DATA
}
}
}
}
}
Verify SSHv2 is configured for protocol V2 only, ciphers [ aes256-ctr ], key-exchange [ ecdh-sha2-nistp521 ecdh-sha2-nistp384 ecdh-sha2-nistp256 ], and macs [ hmac-sha2-512 hmac-sha2-256 ].
[edit system services ssh]
:
protocol-version v2;
ciphers [ aes256-ctr];
macs [ hmac-sha2-512 hmac-sha2-256 ];
key-exchange [ ecdh-sha2-nistp521 ecdh-sha2-nistp384 ecdh-sha2-nistp256 ];
If the network device is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2/FIPS 140-3 approved algorithm, this is a finding.
M
5477