SV-283766r1203597_rule
V-283766
SRG-APP-000119-NDM-000236
NOKI-ND-000260
CAT II
10
Configure the Nokia router to protect audit information from unauthorized modification by configuring authentication servers and applying correct authorization privileges for each user.
Multiple RADIUS servers can be configured per the configuration below:
- configure system security radius
- accounting
- authorization
- server <radius server ip address>
For local accounts, assign the correct user profile to each user:
- configure system security user <user name> console member <profile name>
Users can also be restricted to the user's home directory. If the home directory for the user is not configured, the user does not have access to any directory:
- configure system security user <user name>
- restricted-to-home
If the user requires a directory, it can be configured using the command below:
- home-directory <directory >
Determine if the Nokia router protects audit information from any type of unauthorized modification with such methods as ensuring log files receive the proper file system permissions, limiting log data locations, and leveraging user permissions and roles to identify the user accessing the data and the corresponding user rights.
Verify the authentication server is configured using the command below:
- show system security authentication
Verify authentication servers are configured with correct user privileges to restrict access to the router file system.
Verify each local user has the correct "profile" assigned, the user is "restricted to home", and the "home directory" is defined:
- show system security user detail
If the Nokia router is not configured with external authentication servers, this is a finding.
V-283766
False
NOKI-ND-000260
Determine if the Nokia router protects audit information from any type of unauthorized modification with such methods as ensuring log files receive the proper file system permissions, limiting log data locations, and leveraging user permissions and roles to identify the user accessing the data and the corresponding user rights.
Verify the authentication server is configured using the command below:
- show system security authentication
Verify authentication servers are configured with correct user privileges to restrict access to the router file system.
Verify each local user has the correct "profile" assigned, the user is "restricted to home", and the "home directory" is defined:
- show system security user detail
If the Nokia router is not configured with external authentication servers, this is a finding.
M
5744