SV-216541r531088_rule
V-216541
SRG-APP-000411-NDM-000330
CISC-ND-001200
CAT I
10
Configure the router to use SSH version 2 as shown in the example below.
RP/0/0/CPU0:R3(config)#ssh server v2
Review the router configuration to verify that SSH version 2 is configured as shown in the example below.
ssh server v2
Note: IOS XR supports SSHv1 and SSHv2. SSHv1 uses Rivest, Shamir, and Adelman (RSA) keys while SSHv2 uses Digital Signature Algorithm (DSA) keys which is FIPS 186-4.
If the Cisco router is not configured to use FIPS-validated HMAC to protect the integrity of remote maintenance sessions, this is a finding.
V-216541
False
CISC-ND-001200
Review the router configuration to verify that SSH version 2 is configured as shown in the example below.
ssh server v2
Note: IOS XR supports SSHv1 and SSHv2. SSHv1 uses Rivest, Shamir, and Adelman (RSA) keys while SSHv2 uses Digital Signature Algorithm (DSA) keys which is FIPS 186-4.
If the Cisco router is not configured to use FIPS-validated HMAC to protect the integrity of remote maintenance sessions, this is a finding.
M
4023