CIS Cisco IOS XE 17.x v2.1.0 L1

Audit Details

Name: CIS Cisco IOS XE 17.x v2.1.0 L1

Updated: 6/24/2024

Authority: CIS

Plugin: Cisco

Revision: 1.0

Estimated Item Count: 57

File Details

Filename: CIS_Cisco_IOS_XE_17.x_v2.1.0_L1.audit

Size: 139 kB

MD5: dc922421c991d9dfa73478fbce60ee40
SHA256: 1c746cd3ea4afb672e94c6d49dc39adfc8495f26e7bc389a55ef48f19c112a09

Audit Items

DescriptionCategories
1.1.1 Enable 'aaa new-model'

ACCESS CONTROL

1.1.2 Enable 'aaa authentication login'

ACCESS CONTROL

1.1.3 Enable 'aaa authentication enable default'

ACCESS CONTROL

1.1.4 Set 'login authentication for 'line vty'

ACCESS CONTROL

1.1.5 Set 'login authentication for 'ip http'

ACCESS CONTROL

1.2.1 Set 'privilege 1' for local users

IDENTIFICATION AND AUTHENTICATION

1.2.2 Set 'transport input ssh' for 'line vty' connections

IDENTIFICATION AND AUTHENTICATION

1.2.3 Set 'no exec' for 'line aux 0'

SYSTEM AND INFORMATION INTEGRITY

1.2.4 Create 'access-list' for use with 'line vty'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.2.5 Set 'access-class' for 'line vty'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'

ACCESS CONTROL

1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'

ACCESS CONTROL

1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'

ACCESS CONTROL

1.2.9 Set 'transport input none' for 'line aux 0'

ACCESS CONTROL

1.2.10 Set 'http Secure-server' limit

ACCESS CONTROL

1.2.11 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'

ACCESS CONTROL

1.3.1 Set the 'banner-text' for 'banner exec'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.2 Set the 'banner-text' for 'banner login'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.3 Set the 'banner-text' for 'banner motd'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.4 Set the 'banner-text' for 'webauth banner'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.4.1 Set 'password' for 'enable secret'

ACCESS CONTROL

1.4.2 Enable 'service password-encryption'

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.3 Set 'username secret' for all local users

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.5.1 Set 'no snmp-server' to disable SNMP when unused

SYSTEM AND INFORMATION INTEGRITY

1.5.2 Unset 'private' for 'snmp-server community'

SYSTEM AND INFORMATION INTEGRITY

1.5.3 Unset 'public' for 'snmp-server community'

SYSTEM AND INFORMATION INTEGRITY

1.5.4 Do not set 'RW' for any 'snmp-server community'

SYSTEM AND INFORMATION INTEGRITY

1.5.5 Set the ACL for each 'snmp-server community'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.6 Create an 'access-list' for use with SNMP

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.7 Set 'snmp-server host' when using SNMP

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.8 Set 'snmp-server enable traps snmp'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

2.1.1.1.1 Set the 'hostname'

CONFIGURATION MANAGEMENT

2.1.1.1.2 Set the 'ip domain-name'

CONFIGURATION MANAGEMENT

2.1.1.1.3 Set 'modulus' to greater than or equal to 2048 for 'crypto key generate rsa'

SYSTEM AND SERVICES ACQUISITION

2.1.1.1.4 Set 'seconds' for 'ip ssh timeout' for 60 seconds or less

ACCESS CONTROL

2.1.1.1.5 Set maximum value for 'ip ssh authentication-retries'

IDENTIFICATION AND AUTHENTICATION

2.1.1.2 Set version 2 for 'ip ssh version'

CONFIGURATION MANAGEMENT

2.1.2 Set 'no cdp run'

SYSTEM AND INFORMATION INTEGRITY

2.1.3 Set 'no ip bootp server'

SYSTEM AND INFORMATION INTEGRITY

2.1.4 Set 'no service dhcp'

SYSTEM AND INFORMATION INTEGRITY

2.1.5 Set 'no ip identd'

SYSTEM AND INFORMATION INTEGRITY

2.1.6 Set 'service tcp-keepalives-in'

SYSTEM AND INFORMATION INTEGRITY

2.1.7 Set 'service tcp-keepalives-out'

SYSTEM AND INFORMATION INTEGRITY

2.1.8 Set 'no service pad'

SYSTEM AND INFORMATION INTEGRITY

2.2.1 Set 'logging enable'

AUDIT AND ACCOUNTABILITY

2.2.2 Set 'buffer size' for 'logging buffered'

AUDIT AND ACCOUNTABILITY

2.2.3 Set 'logging console critical'

AUDIT AND ACCOUNTABILITY

2.2.4 Set IP address for 'logging host'

AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY

2.2.5 Set 'logging trap informational'

AUDIT AND ACCOUNTABILITY

2.2.6 Set 'service timestamps debug datetime'

AUDIT AND ACCOUNTABILITY