NET1623 - Authentication required for console access - 'CON port (login authentication AUTH_LIST)'

Information

The network device must require authentication for console access.

Network devices with no password for administrative access via the console provide the opportunity for anyone with physical access to the device to make configuration changes enabling them to disrupt network operations resulting in a network outage.

NOTE: Change 'AAA_LOGIN_LIST' to your organization's AAA group name. If the default list is used for the AAA function then the login authentication list is not displayed in output.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure authentication for console access on the network device.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(3), CAT|I, Rule-ID|SV-19270r4_rule, STIG-ID|NET1623, Vuln-ID|V-4582

Plugin: Cisco

Control ID: 85497820c8a7c8be7f620acd308abfaf187a9e07ae323d1522ceb723fe68b791