STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia router must generate an immediate real-time alert for all audit failure events requiring real-time alerts.

DISA Rule

SV-283777r1203376_rule

Vulnerability Number

V-283777

Group Title

SRG-APP-000360-NDM-000295

Rule Version

NOKI-ND-000640

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nokia router to generate an immediate real-time alert of all audit failure events requiring real-time alerts into a syslog server.

Configure a log file:

- exit all
- configure log log-id <id>
- from main, security, and change
- to syslog <syslog id>

Configure a syslog:

- exit all
- configure log syslog <syslog id>
- address <syslog server ip address>
- level info
- log-prefix <log prefix to be shown in syslog server>
- port <UDP port #>
- timestamp-format millisecond

Configure the syslog server to notify the appropriate personnel.

Check Contents

Verify the external syslog server is configured and online, as shown in the example below:

- show log syslog
# show log syslog

Syslog Target Hosts

Syslog Name
Id Ip Address Port Sev Level
Below Level Drop Facility Prefix
TLS Profile

1
1 1.1.1.1 514 info
0 local7 yes

Verify syslog operation by a configuration change and verify the syslog server has received the entry.

If the syslog server does not receive the configuration change, this is a finding.

If an immediate alert of all audit failure events requiring real-time alerts is not generated, this is a finding.

Vulnerability Number

V-283777

Documentable

False

Rule Version

NOKI-ND-000640

Severity Override Guidance

Verify the external syslog server is configured and online, as shown in the example below:

- show log syslog
# show log syslog

Syslog Target Hosts

Syslog Name
Id Ip Address Port Sev Level
Below Level Drop Facility Prefix
TLS Profile

1
1 1.1.1.1 514 info
0 local7 yes

Verify syslog operation by a configuration change and verify the syslog server has received the entry.

If the syslog server does not receive the configuration change, this is a finding.

If an immediate alert of all audit failure events requiring real-time alerts is not generated, this is a finding.

Check Content Reference

M

Target Key

5744