SV-273835r1110833_rule
V-273835
SRG-APP-000516-NDM-000336
RCKS-NDM-000920
CAT I
10
Configure AAA as needed:
radius-server host x.x.x.x auth-port 1812 acct-port 1813 default key [shared_secret]
radius-server host y.y.y.y auth-port 1812 acct-port 1813 default key [shared_secret]
aaa authentication login default radius local
aaa authorization commands 0 default radius
aaa authorization exec default radius
Verify that AAA authentication and authorization are configured along with RADIUS/TACACS+ servers.
SSH@ICX#show running-config | include (aaa|radius)
aaa authentication dot1x default radius
radius-server host x.x.x.x auth-port 1812 acct-port 1813 default key 2 $VWlkRGkt dot1x mac-auth
radius-server host y.y.y.y auth-port 1812 acct-port 1813 default key 2 $UGlkRGktdG5v dot1x mac-auth
radius-server key 2 $UGlkRGktdG5v
aaa authentication login default radius local
aaa authorization commands 0 default radius
aaa authorization exec default radius
If two central authentication servers are not configured, this is a finding.
V-273835
False
RCKS-NDM-000920
Verify that AAA authentication and authorization are configured along with RADIUS/TACACS+ servers.
SSH@ICX#show running-config | include (aaa|radius)
aaa authentication dot1x default radius
radius-server host x.x.x.x auth-port 1812 acct-port 1813 default key 2 $VWlkRGkt dot1x mac-auth
radius-server host y.y.y.y auth-port 1812 acct-port 1813 default key 2 $UGlkRGktdG5v dot1x mac-auth
radius-server key 2 $UGlkRGktdG5v
aaa authentication login default radius local
aaa authorization commands 0 default radius
aaa authorization exec default radius
If two central authentication servers are not configured, this is a finding.
M
5695