SV-255961r961557_rule
V-255961
SRG-APP-000412-NDM-000331
ARST-ND-000700
CAT I
10
Configure the Arista network device to use FIPS-approved algorithms to protect the confidentiality of remote maintenance sessions.
switch(config)#management ssh
switch(config-mgmt-ssh)#cipher aes256-ctr aes512-ctr aes128-ctr
Validate that a FIPS validated SSH encryption algorithm is selected.
NOTE: AES-CBC algorithms have been considered compromised and are no longer recommended for cryptographic algorithms. AES-CTR and AES-GCM are both superior algorithms and are recommended.
sh run | section management ssh
cipher aes256-ctr aes512-ctr aes128-ctr
If the Arista network device is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm, this is a finding.
V-255961
False
ARST-ND-000700
Validate that a FIPS validated SSH encryption algorithm is selected.
NOTE: AES-CBC algorithms have been considered compromised and are no longer recommended for cryptographic algorithms. AES-CTR and AES-GCM are both superior algorithms and are recommended.
sh run | section management ssh
cipher aes256-ctr aes512-ctr aes128-ctr
If the Arista network device is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm, this is a finding.
M
5511