Item Search

NameAudit NamePluginCategory
aaa authDISA STIG Cisco IOS Switch NDM v3r2Cisco
accountDISA STIG Cisco IOS Switch NDM v3r2Cisco
Check for mplsDISA STIG Cisco IOS Switch RTR v3r1Cisco
Check for multicast-routing or pimDISA STIG Cisco IOS Switch RTR v3r1Cisco
Check for reduced vtyDISA STIG Cisco IOS Switch NDM v3r2Cisco
Check for udld enable globallyDISA STIG Cisco IOS Switch L2S v3r1Cisco
Check if Cisco IOS is installedDISA STIG Cisco IOS Switch NDM v3r2Cisco
Check if LLDP is disabledDISA STIG Cisco IOS Switch RTR v3r1Cisco
CISC-L2-000210 - The Cisco switch must have all disabled switch ports assigned to an unused VLAN.DISA STIG Cisco IOS Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000260 - The Cisco switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.DISA STIG Cisco IOS Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000160 - The Cisco switch must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.DISA STIG Cisco IOS Switch NDM v3r2Cisco

ACCESS CONTROL

CISC-ND-000210 - The Cisco device must be configured to audit all administrator activity.DISA STIG Cisco IOS Switch NDM v3r2Cisco

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

CISC-ND-001220 - The Cisco switch must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.DISA STIG Cisco IOS Switch NDM v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000180 - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) mask reply messages disabled on all external interfaces.DISA STIG Cisco IOS Switch RTR v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000200 - The Cisco switch must be configured to log all packets that have been dropped at interfaces via an access control list (ACL).DISA STIG Cisco IOS Switch RTR v3r1Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000220 - The Cisco switch must be configured to produce audit records containing information to establish the source of the events.DISA STIG Cisco IOS Switch RTR v3r1Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000236 - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.DISA STIG Cisco IOS Switch RTR v3r1Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000237 - The Cisco switch must not be configured to use IPv6 Site Local Unicast addresses.DISA STIG Cisco IOS Switch RTR v3r1Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000770 - The Cisco P switch must be configured to enforce a Quality-of-Service (QoS) policy to provide preferred treatment for mission-critical applications.DISA STIG Cisco IOS Switch RTR v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000790 - The Cisco multicast switch must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.DISA STIG Cisco IOS Switch RTR v3r1Cisco

ACCESS CONTROL

CISC-RT-000800 - The Cisco multicast switch must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.DISA STIG Cisco IOS Switch RTR v3r1Cisco

ACCESS CONTROL

CISC-RT-000890 - The Cisco multicast Designated switch (DR) must be configured to set the shortest-path tree (SPT) threshold to infinity to minimalize source-group (S, G) state within the multicast topology where Any Source Multicast (ASM) is deployed.DISA STIG Cisco IOS Switch RTR v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

crypto pki trustpointDISA STIG Cisco IOS Switch NDM v3r2Cisco
deny 0.0.0.0DISA STIG Cisco IOS Switch RTR v3r1Cisco
deny 127.0.0.0DISA STIG Cisco IOS Switch RTR v3r1Cisco
deny 240.0.0.0DISA STIG Cisco IOS Switch RTR v3r1Cisco
dest-option-type 2DISA STIG Cisco IOS Switch RTR v3r1Cisco
dest-option-type 13DISA STIG Cisco IOS Switch RTR v3r1Cisco
dest-option-type 16DISA STIG Cisco IOS Switch RTR v3r1Cisco
dest-option-type 36DISA STIG Cisco IOS Switch RTR v3r1Cisco
dest-option-type 39DISA STIG Cisco IOS Switch RTR v3r1Cisco
dest-option-type 47DISA STIG Cisco IOS Switch RTR v3r1Cisco
dot1x system-auth-controlDISA STIG Cisco IOS Switch L2S v3r1Cisco
GEN002860 - Audit logs must be rotated daily.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

interfaceDISA STIG Cisco IOS Switch RTR v3r1Cisco
ipDISA STIG Cisco IOS Switch RTR v3r1Cisco
ip dhcp snooping vlanDISA STIG Cisco IOS Switch L2S v3r1Cisco
ip igmp snoopingDISA STIG Cisco IOS Switch L2S v3r1Cisco
ip unreachablesDISA STIG Cisco IOS Switch RTR v3r1Cisco
ipv6DISA STIG Cisco IOS Switch RTR v3r1Cisco
line vtyDISA STIG Cisco IOS Switch NDM v3r2Cisco
login on-successDISA STIG Cisco IOS Switch NDM v3r2Cisco
ntp authentication-keyDISA STIG Cisco IOS Switch NDM v3r2Cisco
outside interfaceDISA STIG Cisco IOS Switch RTR v3r1Cisco
outside-interfaceDISA STIG Cisco IOS Switch RTR v3r1Cisco
snmp-server groupDISA STIG Cisco IOS Switch NDM v3r2Cisco
snmp-server hostDISA STIG Cisco IOS Switch NDM v3r2Cisco
snmp-server viewDISA STIG Cisco IOS Switch NDM v3r2Cisco
spanning-tree loopguardDISA STIG Cisco IOS Switch L2S v3r1Cisco
spanning-tree modeDISA STIG Cisco IOS Switch L2S v3r1Cisco