1.5.10 Require 'aes 128' as minimum for 'snmp-server user' when using SNMPv3

Information

Specify the use of a minimum of 128-bit AES algorithm for encryption when using SNMPv3.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

NOTE: If performing an offline config audit this check may not show results.

Solution

For each SNMPv3 user created on your router add privacy options by issuing the following command.
hostname(config)#snmp-server user {user_name} {group_name} v3 encrypted auth sha {auth_password} priv aes 128 {priv_password} {acl_name_or_number}

See Also

https://workbench.cisecurity.org/files/508

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(1), CSCv7|4.5

Plugin: Cisco

Control ID: ee485652e015d1b3bee2516c7da96db93fae56ec18ac3db03aa6a63ccef141b5