NET1636 - The network device must require authentication prior to establishing a management connection for administrative access - Classes

Information

Network devices with no password for administrative access via a management connection provide the opportunity for anyone with network access to the device to make configuration changes enabling them to disrupt network operations resulting in a network outage.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure authentication for all management connections.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R27_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CAT|I, Rule-ID|SV-28748r3_rule, STIG-ID|NET1636, Vuln-ID|V-3175

Plugin: Juniper

Control ID: 9633689dc464d8fbaa4020c9b11cc20cf31786a40b2e8267975a22449a56fa8e