NET1660 - The network device must use SNMPv3 Security Model with FIPS 140-2 validated cryptography - authentication-none

Information

SNMP Versions 1 and 2 are not considered secure. Without the strong authentication and privacy that is provided by the SNMP Version 3 User-based Security Model (USM), an unauthorized user can gain access to network management information used to launch an attack against the network.

Solution

If SNMP is enabled, configure the network device to use SNMP Version 3 Security Model with FIPS 140-2 validated cryptography (i.e., SHA authentication and AES encryption).

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R27_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|I, Rule-ID|SV-3196r4_rule, STIG-ID|NET1660, Vuln-ID|V-3196

Plugin: Juniper

Control ID: 19f473ce71a5695cb1858c5b3aa017e290b6d4818dafee3caf24641fb5bf3587