STIGQter STIGQter: STIG Summary: Riverbed NetProfiler Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Riverbed NetProfiler must be configured to protect against known types of denial-of-service (DOS) attacks by restricting web and SSH access to the appliance.

DISA Rule

SV-256091r961620_rule

Vulnerability Number

V-256091

Group Title

SRG-APP-000435-NDM-000315

Rule Version

RINP-DM-000055

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Go to configuration >> Appliance Security >> Password Security.

Under Access >> Remote Access, select the "Restrict Web access to" radio button and the "Restrict SSH access to" radio button, and fill the corresponding boxes with the authorized range of IP addresses.

Check Contents

Go to configuration >> Appliance Security >> Password Security.

Under Access >> Remote Access, verify the "Restrict Web access to" radio button and the "Restrict SSH access to" radio button are selected, and the boxes contain the authorized range of IP addresses.

If this is not set, this is a finding.

Vulnerability Number

V-256091

Documentable

False

Rule Version

RINP-DM-000055

Severity Override Guidance

Go to configuration >> Appliance Security >> Password Security.

Under Access >> Remote Access, verify the "Restrict Web access to" radio button and the "Restrict SSH access to" radio button are selected, and the boxes contain the authorized range of IP addresses.

If this is not set, this is a finding.

Check Content Reference

M

Target Key

5514