STIGQter STIGQter: STIG Summary: Riverbed NetIM NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The Riverbed NetIM must be configured to use an authentication server configured for multifactor authentication (MFA) using DOD PKI for the purpose of authenticating users prior to granting administrative access.

DISA Rule

SV-275461r1148276_rule

Vulnerability Number

V-275461

Group Title

SRG-APP-000516-NDM-000336

Rule Version

RIIM-DM-000015

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Although all individual admin accounts must be configured on an authentication server, the NetIM must be configured to point to a DOD PKI-based authentication server and roles must be mapped to the authorization attributes on the authentication server. Check the SSP to see which roles are required to be defined for remote user.

1. Navigate to the installation directory typically located at /data1/riverbed/NetIM/<install_dir > and run the following command:

$ app.sh /TACACS_STATE enabled

2. From the GUI, navigate to Configure >> All Settings >> Integrate >> TACACS+.
3. On the TACACS+ Configurations page, fill out all required information. Add the IP address for the authentication server, add a role for the remote user, and check "Require Authentication".
4. Select "Require Authorization" and provide the authorization attributes and role attributes.

To add, modify, or delete a user account or log off a user, follow these steps:

1. Navigate to Configure >> All Settings >> Administer >> User Management.
2. To add a TACACS+ user, click the "+" icon next to "Create TACACS+ user".
3. Select a valid TACACS+ username, assign a role from the dropdown list, then click "Save". For audit administrator, assign the role of USER_AUDITOR. For the default GUI "admin" account, the name must be changed.

Note: The TACACS+ server must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.

Check Contents

Review the AAA configuration.

Navigate to the GUI portal admin user login screen. If TACACS+ is configured, the NetIM login screen presents only the option to use TACACS.

If TACACS+ is not configured, this is a finding.

Vulnerability Number

V-275461

Documentable

False

Rule Version

RIIM-DM-000015

Severity Override Guidance

Review the AAA configuration.

Navigate to the GUI portal admin user login screen. If TACACS+ is configured, the NetIM login screen presents only the option to use TACACS.

If TACACS+ is not configured, this is a finding.

Check Content Reference

M

Target Key

5704