Tenable ZTE ROSNG Best Practices

Audit Details

Name: Tenable ZTE ROSNG Best Practices

Updated: 8/19/2026

Authority: TNS

Plugin: ZTE_ROSNG

Revision: 1.0

Estimated Item Count: 49

File Details

Filename: Tenable-ZTE_ROSNG-Best-Practice-v1.1.0.audit

Size: 162 kB

MD5: 2e7bceeb278529576a1df11f9e597a87
SHA256: 7ac00747dccb7fd6fbcc325b9f259bf5daf105f6301ca0d5d587c01bbf4cc016

Audit Items

DescriptionCategories
1.1 Secure Login and telnet Disabling - Disable telnet server
1.1 Secure Login and telnet Disabling - Enable SSH server
1.2 Password Security Policy - a) The default password length shouldn't be below 8 characters
1.2 Password Security Policy - b) The password must include either three of 'number', 'capital', 'lowercase', 'special-character' or set the 'character-set-num' value to 3-4
1.2 Password Security Policy - c) Configure 'strong-password dictionary' and 'same-consecutive' to avoid weak password - same-consecutive
1.2 Password Security Policy - c) Configure 'strong-password dictionary' and 'same-consecutive' to avoid weak password - strong-password dictionary
1.2 Password Security Policy - d) Display password in cipher text
1.2 Password Security Policy - e) Check for strong-password date-check enable
1.2 Password Security Policy - e) Check for strong-password max-length
1.2 Password Security Policy - e) Check for strong-password username-related-chk inverse
1.2 Password Security Policy - f) The validity period of an account can be configured
1.3 Account Anti-riot Attack
1.4 SNMP Security - a) SNMP Community Security
1.4 SNMP Security - b) SNMP Security Protection Function
1.5 FTP/SFTP Access Authorization - login-type-allowed
1.5 FTP/SFTP Access Authorization - sftp top-directory
1.6 Support Web Access Security - a) ciphersuite
1.6 Support Web Access Security - b) ssl-context field
1.6 Support Web Access Security - c) version
1.7 Log Auditing

AUDIT AND ACCOUNTABILITY

1.8 SSH Strong Algorithm - a) Disable encryption none
1.8 SSH Strong Algorithm - b) Disable encryption 3des-cbc
1.8 SSH Strong Algorithm - c) Disable encryption aes128-cbc
1.8 SSH Strong Algorithm - d) Disable encryption aes192-cbc
1.8 SSH Strong Algorithm - e) Disable encryption aes256-cbc
1.8 SSH Strong Algorithm - f) Disable encryption blowfish-cbc
1.8 SSH Strong Algorithm - g) Disable hmac md5
1.8 SSH Strong Algorithm - h) Disable hmac none
1.8 SSH Strong Algorithm - i) Disable diffie-hellman group-exchange-sha1
1.8 SSH Strong Algorithm - j) Disable diffie-hellman group1-sha1
1.8 SSH Strong Algorithm - k) Disable hmac sha1
1.9 SSL Strong Algorithm - a) Version
1.9 SSL Strong Algorithm - b) ciphersuite
1.9 SSL Strong Algorithm - c) pki-profile
1.9 SSL Strong Algorithm - d) renegotiate
2.2 NTP Security Protection - a) Enable NTP

AUDIT AND ACCOUNTABILITY

2.2 NTP Security Protection - b) NTP access-group

AUDIT AND ACCOUNTABILITY

2.2 NTP Security Protection - c) NTP Auth-key MD5 or Keychain

AUDIT AND ACCOUNTABILITY

2.3 Disable the Proxy ARP Function - a) No proxy
2.3 Disable the Proxy ARP Function - b) No inter-vlan-proxy
2.3 Disable the Proxy ARP Function - c) No proxy local
2.3 Disable the Proxy ARP Function - d) No local-proxy-arp
2.4 Disable the IP Unreachable Function
2.5 Product Default Banner
3.1 Authentication and Verification of OSPFv2 Routing Protocols - authentication message-digest-key/keychain
3.1 Authentication and Verification of OSPFv3 Routing Protocols - authentication keychain/ipsec
3.2 Authentication and Verification of ISIS Routing Protocols - authentication-type hmac-md5/authentication-keychain
3.3 Authentication and Verification of BGP Routing Protocols
Tenable ZTE ROSNG Best Practices