SV-216531r531088_rule
V-216531
SRG-APP-000156-NDM-000250
CISC-ND-000530
CAT II
10
Configure the router to use SSH version 2 as shown in the example below.
RP/0/0/CPU0:R3(config)#ssh server v2
Review the router configuration to verify that SSH version 2 is configured as shown in the example below.
ssh server v2
Note: IOS XR supports SSHv1 and SSHv2. SSHv1 uses Rivest, Shamir, and Adelman (RSA) keys while SSHv2 uses Digital Signature Algorithm (DSA) keys.
If the router is not configured to implement replay-resistant authentication mechanisms for network access to privileged accounts, this is a finding.
V-216531
False
CISC-ND-000530
Review the router configuration to verify that SSH version 2 is configured as shown in the example below.
ssh server v2
Note: IOS XR supports SSHv1 and SSHv2. SSHv1 uses Rivest, Shamir, and Adelman (RSA) keys while SSHv2 uses Digital Signature Algorithm (DSA) keys.
If the router is not configured to implement replay-resistant authentication mechanisms for network access to privileged accounts, this is a finding.
M
4023