STIGQter STIGQter: STIG Summary:

Arista MLS EOS 4.X NDM Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 02 Apr 2025

CheckedNameTitle
SV-255947r960735_ruleThe Arista network device must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
SV-255948r991781_ruleThe Arista network device must enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.
SV-255949r960840_ruleThe Arista network device must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-255950r960843_ruleThe Arista network device must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.
SV-255951r960777_ruleThe Arista network device must be configured to audit all administrator activity.
SV-255952r1043177_ruleThe Arista network device must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
SV-255953r1051115_ruleThe Arista network device must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-255954r1015710_ruleThe Arista network device must enforce a minimum 15-character password length.
SV-255955r961050_ruleThe Arista network device must use FIPS 140-2 approved algorithms for authentication to a cryptographic module.
SV-255956r991784_ruleThe Arista network device must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements.
SV-255957r987662_ruleIf the Arista network device uses role-based access control, the network device must enforce organization-defined role-based access control policies over defined subjects and objects.
SV-255958r1015711_ruleThe Arista network device must be configured to synchronize internal system clocks using redundant authenticated time sources.
SV-255959r961506_ruleThe Arista network device must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
SV-255960r961554_ruleThe Arista network devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.
SV-255961r961557_ruleThe Arista network device must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.
SV-255962r960891_ruleThe Arista network device must be configured to capture all DOD auditable events.
SV-255963r961863_ruleThe network device must be configured to use an authentication server to authenticate users prior to granting administrative access.
SV-255964r961863_ruleThe network device must be configured to conduct backups of system level information contained in the information system when changes occur.
SV-255965r961863_ruleThe Arista network device must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-255966r961863_ruleThe Arista network Arista device must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the ISSO.
SV-255967r961863_ruleThe Arista network device must be running an operating system release that is currently supported by the vendor.