SV-273825r1110845_rule
V-273825
SRG-APP-000395-NDM-000310
RCKS-NDM-000730
CAT II
10
Delete any SNMP users not configured for SHA/AES. Configure SNMP user account for SHA/AES.
SSH@ICX(config)#snmp-server user test_admin test_group v3 auth sha256 [security-string] priv aes [security-key]
View SNMP users:
SSH@ICX# show snmp user
username = admin1
acl name = <none>
group = lab
security model = v3
group acl name = <none>
group ipv6 acl name = <none>
authtype = sha
authkey = 6e3e368283194dffcdabde95c9c44e795de911c2
privtype = aes
privkey = c8b94fccfc1c845ed8a0d7b172405feb
engine ID= 80 0 7c7 3d4c19e609a58
If any users are not configured for authtype sha, this is a finding.
V-273825
False
RCKS-NDM-000730
View SNMP users:
SSH@ICX# show snmp user
username = admin1
acl name = <none>
group = lab
security model = v3
group acl name = <none>
group ipv6 acl name = <none>
authtype = sha
authkey = 6e3e368283194dffcdabde95c9c44e795de911c2
privtype = aes
privkey = c8b94fccfc1c845ed8a0d7b172405feb
engine ID= 80 0 7c7 3d4c19e609a58
If any users are not configured for authtype sha, this is a finding.
M
5695