STIGQter STIGQter: STIG Summary: Arista MLS DCS-7000 Series NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 25 Oct 2019:

The Arista Multilayer Switch must be configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

DISA Rule

SV-75323r1_rule

Vulnerability Number

V-60865

Group Title

SRG-APP-000373-NDM-000298

Rule Version

AMLS-NM-000280

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the network device to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

Configuration Example:

switch(config)#ntp server HOST
switch(config)#ntp server HOST prefer

Check Contents

Determine if the network device is configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

If the network device is not configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources, this is a finding.

Verify with:

switch#show NTP status

Identify the NTP status and available time sources.

Vulnerability Number

V-60865

Documentable

False

Rule Version

AMLS-NM-000280

Severity Override Guidance

Determine if the network device is configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

If the network device is not configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources, this is a finding.

Verify with:

switch#show NTP status

Identify the NTP status and available time sources.

Check Content Reference

M

Target Key

2825

Comments