STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia router must be configured to use at least two authentication servers for authenticating users prior to granting administrative access.

DISA Rule

SV-283785r1203604_rule

Vulnerability Number

V-283785

Group Title

SRG-APP-000516-NDM-000336

Rule Version

NOKI-ND-000890

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

1. Configure the Nokia router to use at least two authentication servers.

Nokia router supports RADIUS, TACACS+, and LDAP for user authentication. Multiple authentication servers can be configured. The example below is for the TACACS configuration:

- configure system security tacplus server <index> address <tacacs+ server ip address>

2. Configure the authentication order to use the authentication servers as the primary source for authentication. Up to four methods of authentication order can be configured:

- configure system security password authentication-order <first order can be: local, radius, tacplus or ldap> <2nd order can be: local, radius, tacplus or ldap> <3rd order can be: local, radius, tacplus or ldap> <4th order can be: local, radius, tacplus or ldap>

3. Configure all network connections associated with a device management to use the authentication servers for login authentication.

Check Contents

Review the Nokia router configuration to verify the device is configured to use at least two authentication servers as the primary source for authentication.

Verify multiple authentication servers are configured and status is "up", as shown in the example below:

- show system security authentication statistics
show system security authentication statistics

Authentication sequence : radius tacplus ldap local

type status timeout (secs) retry count
server address retry timeout
server name (secs)

radius up 3 3
192.168.0.10:1812 n/a
tacplus up 3 n/a
192.168.1.10:49 300
ldap up 3 3
10.1.1.1:389 n/a
Corporate LDAP Server

radius admin/oper status : up/up
UDP port : 1812
TCP port : 2083
tacplus admin/oper status : up/up
ldap admin/oper status : up/up
health check : enabled (interval 30 secs)

No. of Servers: 3

If the Nokia router is not configured to use at least two authentication servers for authenticating users prior to granting administrative access, this is a finding.

Vulnerability Number

V-283785

Documentable

False

Rule Version

NOKI-ND-000890

Severity Override Guidance

Review the Nokia router configuration to verify the device is configured to use at least two authentication servers as the primary source for authentication.

Verify multiple authentication servers are configured and status is "up", as shown in the example below:

- show system security authentication statistics
show system security authentication statistics

Authentication sequence : radius tacplus ldap local

type status timeout (secs) retry count
server address retry timeout
server name (secs)

radius up 3 3
192.168.0.10:1812 n/a
tacplus up 3 n/a
192.168.1.10:49 300
ldap up 3 3
10.1.1.1:389 n/a
Corporate LDAP Server

radius admin/oper status : up/up
UDP port : 1812
TCP port : 2083
tacplus admin/oper status : up/up
ldap admin/oper status : up/up
health check : enabled (interval 30 secs)

No. of Servers: 3

If the Nokia router is not configured to use at least two authentication servers for authenticating users prior to granting administrative access, this is a finding.

Check Content Reference

M

Target Key

5744