SV-75315r1_rule
V-60857
SRG-APP-000190-NDM-000267
AMLS-NM-000240
CAT II
10
Configure the network device to terminate the connection associated with a device management session at the end of the session or after 10 minutes of inactivity.
Arista switches have a configurable timeout function that automatically closes connections to the switch upon reaching an organization-defined period of time.
Configuration Example:
switch(config)#management ssh
switch(config-mgmt-ssh)#idle-timeout 10
Configure the switch to terminate an idle ssh connection after 10 minutes of inactivity.
Determine if the network device terminates the connection associated with a device management session at the end of the session or after 10 minutes of inactivity. This requirement may be verified by demonstration or configuration review.
Verify by executing a "show running-config" command, and under the "management ssh" subsection, validate the configuration statement "idle-timeout 10" is present and the value is 10 or less.
If the network device does not terminate the connection associated with a device management session at the end of the session or after 10 minutes of inactivity, this is a finding.
V-60857
False
AMLS-NM-000240
Determine if the network device terminates the connection associated with a device management session at the end of the session or after 10 minutes of inactivity. This requirement may be verified by demonstration or configuration review.
Verify by executing a "show running-config" command, and under the "management ssh" subsection, validate the configuration statement "idle-timeout 10" is present and the value is 10 or less.
If the network device does not terminate the connection associated with a device management session at the end of the session or after 10 minutes of inactivity, this is a finding.
M
2825