STIGQter STIGQter: STIG Summary: Riverbed NetIM NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The Riverbed NetIM must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).

DISA Rule

SV-275488r1147514_rule

Vulnerability Number

V-275488

Group Title

SRG-APP-000395-NDM-000310

Rule Version

RIIM-DM-000049

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure NetIM to authenticate SNMP messages using a FIPS-validated HMAC.

1. In the GUI, navigate to Configure >> All Settings >> Discover >> Global Discovery Settings.
2. Click "SNMP v3 Credentials".
3. In the Add SNMP v3 Credentials box, select the following:
Security Level menu = AUTH_PRIV
Auth Protocol = <protocol>

Where <protocol> is one of the following for Auth Protocol HMAC192_SHA256, HMAC256_SHA384, or HMAC384_SHA512.

Priv Protocol = <protocol>

Where <protocol> is one of the following for Priv Protocol CFB_AES_192, CFB_AES_256

Note: FIPS compliance requires Version 2.10 or higher and a Ubuntu Pro license, both of which are covered in other CAT 1 requirements.

Check Contents

Verify NetIM is configured to authenticate SNMP messages using a FIPS-validated HMAC.

1. In the GUI, navigate to Configure >> All Settings >> Discover >> Global Discovery Settings.
2. Click "SNMP v3 Credentials".
3. In the Add SNMP v3 Credentials box, verify the following is configured:
Security Level menu = AUTH_PRIV
Auth Protocol = <protocol>

Where <protocol> is one of the following for Auth Protocol HMAC192_SHA256, HMAC256_SHA384, or HMAC384_SHA512

Priv Protocol = <cipher_protocol>

Where <protocol> is one of the following for Priv Protocol CFB_AES_192, CFB_AES_256

If SNMP messages are not authenticated using a FIPS-validated HMAC, this is a finding.

Vulnerability Number

V-275488

Documentable

False

Rule Version

RIIM-DM-000049

Severity Override Guidance

Verify NetIM is configured to authenticate SNMP messages using a FIPS-validated HMAC.

1. In the GUI, navigate to Configure >> All Settings >> Discover >> Global Discovery Settings.
2. Click "SNMP v3 Credentials".
3. In the Add SNMP v3 Credentials box, verify the following is configured:
Security Level menu = AUTH_PRIV
Auth Protocol = <protocol>

Where <protocol> is one of the following for Auth Protocol HMAC192_SHA256, HMAC256_SHA384, or HMAC384_SHA512

Priv Protocol = <cipher_protocol>

Where <protocol> is one of the following for Priv Protocol CFB_AES_192, CFB_AES_256

If SNMP messages are not authenticated using a FIPS-validated HMAC, this is a finding.

Check Content Reference

M

Target Key

5704