SV-82585r1_rule
V-68095
SRG-APP-000411-NDM-000330
AADC-NM-000144
CAT II
10
The following commands enable management access to the device and the use of SSH, HTTPS, Syslog, and SNMP:
enable-management
service ssh https syslog snmp snmp-trap
Disable HTTP on the management interface:
no enable-management service http management
Note: Do not configure any management protocols on any of the other interfaces.
Disable the web server (HTTP for management):
no web-service server
Review the device configuration.
The following command shows the types of management access allowed on each of the interfaces:
show management [ipv4 | ipv6]
The following command shows IPv4 management access information:
show management ipv4
If either Telnet or HTTP is listed as "on" for any interface, this is a finding.
The following command shows IPv6 management access information:
show management ipv6
If either Telnet or HTTP is listed as "on" for any interface, this is a finding.
Verify that HTTP for management is disabled.
show web-service
If HTTP is enabled, this is a finding.
HTTPS is allowed for management and is enabled by default.
V-68095
False
AADC-NM-000144
Review the device configuration.
The following command shows the types of management access allowed on each of the interfaces:
show management [ipv4 | ipv6]
The following command shows IPv4 management access information:
show management ipv4
If either Telnet or HTTP is listed as "on" for any interface, this is a finding.
The following command shows IPv6 management access information:
show management ipv6
If either Telnet or HTTP is listed as "on" for any interface, this is a finding.
Verify that HTTP for management is disabled.
show web-service
If HTTP is enabled, this is a finding.
HTTPS is allowed for management and is enabled by default.
M
2915