TNS Huawei VRP Best Practice Audit

Audit Details

Name: TNS Huawei VRP Best Practice Audit

Updated: 6/17/2024

Authority: TNS

Plugin: Huawei

Revision: 1.9

Estimated Item Count: 41

File Details

Filename: TNS_Huawei_VRP_Best_Practices.audit

Size: 36.7 kB

MD5: b318201a721816c8c299f3aa2a0e3cd8
SHA256: 30c8c38bb5ddbf07b389a834433a3e21be744e8675e09f8e32431ad5e6faba38

Audit Items

DescriptionCategories
Huawei: Command Levels Not Changed

CONFIGURATION MANAGEMENT

Huawei: Configure appropriate External Syslog server

AUDIT AND ACCOUNTABILITY

Huawei: Configure appropriate NTP server

AUDIT AND ACCOUNTABILITY

Huawei: Device clock = UTC

CONFIGURATION MANAGEMENT

Huawei: Device clock disable DST adjustment

CONFIGURATION MANAGEMENT

Huawei: Disable FTP IPV4

CONFIGURATION MANAGEMENT

Huawei: Disable FTP IPV6

CONFIGURATION MANAGEMENT

Huawei: Disable SNMP write access

ACCESS CONTROL

Huawei: Disable Telnet on IPV4

CONFIGURATION MANAGEMENT

Huawei: Disable Telnet on IPV6

CONFIGURATION MANAGEMENT

Huawei: Enable AAA accounting

IDENTIFICATION AND AUTHENTICATION

Huawei: Enable AAA authentication

IDENTIFICATION AND AUTHENTICATION

Huawei: Enable AAA authorization

IDENTIFICATION AND AUTHENTICATION

Huawei: Enable SNMP Traps

AUDIT AND ACCOUNTABILITY

Huawei: Enable SSH

SYSTEM AND COMMUNICATIONS PROTECTION

Huawei: External Syslog server is configured
Huawei: HTTPS Server is configured
Huawei: HTTPS Server is not configured
Huawei: HTTPS Server requires SSL policy

SYSTEM AND COMMUNICATIONS PROTECTION

Huawei: Information Center is not disabled.

AUDIT AND ACCOUNTABILITY

Huawei: Insecure HTTP is not configured.

CONFIGURATION MANAGEMENT

Huawei: NTP is enabled

AUDIT AND ACCOUNTABILITY

Huawei: Require Group for SNMPv3 Access

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

Huawei: Require service timestamp

AUDIT AND ACCOUNTABILITY

Huawei: Require SSH version 2
Huawei: Review Device Info/Version

CONFIGURATION MANAGEMENT

Huawei: Set 'login' header

ACCESS CONTROL

Huawei: Set 'shell' header

ACCESS CONTROL

Huawei: Set appropriate 'login' header

ACCESS CONTROL

Huawei: Set appropriate 'shell' header

ACCESS CONTROL

Huawei: Set super password

IDENTIFICATION AND AUTHENTICATION

Huawei: Set System Name

CONFIGURATION MANAGEMENT

Huawei: Simple Password Authentication is not used.

IDENTIFICATION AND AUTHENTICATION

Huawei: SNMP appropriate trap host

AUDIT AND ACCOUNTABILITY

Huawei: SNMP Community string != private

IDENTIFICATION AND AUTHENTICATION

Huawei: SNMP Community string != public

IDENTIFICATION AND AUTHENTICATION

Huawei: SNMP is Configured
Huawei: SSH Max Retries <= 3

ACCESS CONTROL

Huawei: User Interfaces are Authenticated

IDENTIFICATION AND AUTHENTICATION

Huawei: User Interfaces Configured Inbound SSH

CONFIGURATION MANAGEMENT

Huawei: User Interfaces Idle Timeout Less Than 5 Minutes

ACCESS CONTROL