SV-77437r1_rule
V-62947
SRG-APP-000516-NDM-000338
RICX-DM-000094
CAT II
10
Configure RiOS to employ automated mechanisms to centrally verify authentication settings.
Navigate to the device Management Console
Navigate to Configure >> Security >> TACACS+
Click "Add a TACACS+ Server"
Set "Hostname or IP Address" to the hostname or IP address of the TACACS+ server
Set "Enabled"
Click "Add"
Click "Set a Global Default Key"
Set the value of "Global Key" to the required value
Set the value of "Confirm Global Key" to the required value
Click "Apply"
Navigate to the top of the web page and click "Save" to save these settings permanently
-- or --
Navigate to Configure >> Security >> RADIUS
Click "Add a RADIUS Server"
Set "Hostname or IP Address" to the hostname or IP address of the RADIUS server
Set the value of "Authentication Port" to the appropriate value
Set the value of "Authentication Type" to "CHAP"
Set "Enabled"
Click "Add"
Click "Set a Global Default Key"
Set the value of "Global Key" to the required value
Set the value of "Confirm Global Key" to the required value
Click "Apply"
Navigate to the top of the web page and click "Save" to save these settings permanently
Verify that RiOS is configured to employ automated mechanisms to centrally verify authentication settings.
Navigate to the device Management Console
Navigate to Configure >> Security >> TACACS+
Verify that "TACACS+ Servers" has at least one server defined
-- or --
Navigate to Configure >> Security >> RADIUS
Verify that "RADIUS Servers" has at least one server defined
If no servers exist in "TACACS+ Servers" or "RADIUS Servers", this is a finding.
V-62947
False
RICX-DM-000094
Verify that RiOS is configured to employ automated mechanisms to centrally verify authentication settings.
Navigate to the device Management Console
Navigate to Configure >> Security >> TACACS+
Verify that "TACACS+ Servers" has at least one server defined
-- or --
Navigate to Configure >> Security >> RADIUS
Verify that "RADIUS Servers" has at least one server defined
If no servers exist in "TACACS+ Servers" or "RADIUS Servers", this is a finding.
M
2931