STIGQter STIGQter: STIG Summary: Riverbed NetProfiler Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Riverbed NetProfiler must be configured to authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.

DISA Rule

SV-256089r961506_rule

Vulnerability Number

V-256089

Group Title

SRG-APP-000395-NDM-000347

Rule Version

RINP-DM-000052

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Go to Administration >> General Settings.

Under "Time Configuration", change the "Encryption" for the NTP Servers to "SHA-1", and under the Key and Index columns, enter the value that corresponds to each NTP server.

Check Contents

Go to Administration >> General Settings.

Under "Time Configuration", verify the "Encryption" for the NTP servers is set to "SHA-1" and the Key and Index columns have a value that corresponds to each NTP server.

If SHA-1 is not configured for the NTP servers, this is a finding.

Vulnerability Number

V-256089

Documentable

False

Rule Version

RINP-DM-000052

Severity Override Guidance

Go to Administration >> General Settings.

Under "Time Configuration", verify the "Encryption" for the NTP servers is set to "SHA-1" and the Key and Index columns have a value that corresponds to each NTP server.

If SHA-1 is not configured for the NTP servers, this is a finding.

Check Content Reference

M

Target Key

5514