Item Search

NameAudit NamePluginCategory
3.1.2 Ensure packet redirect sending is disabled - all sysctlCIS Debian 8 Server L1 v2.0.2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1 Ensure packet redirect sending is disabledCIS Debian Linux 10 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

3.2.1 Ensure packet redirect sending is disabled - all /etc/sysctl.conf /etc/sysctl.d/*CIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.2.1 Ensure packet redirect sending is disabled - default /etc/sysctl.conf /etc/sysctl.d/*CIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.2.2 Ensure packet redirect sending is disabled - 'net.ipv4.conf.default.send_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS CentOS 6 Workstation L1 v3.0.0Unix

CONFIGURATION MANAGEMENT

3.3.2 Ensure packet redirect sending is disabledCIS AlmaLinux OS 9 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

3.3.2 Ensure packet redirect sending is disabledCIS Debian Linux 11 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

3.3.2 Ensure packet redirect sending is disabledCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

3.3.2 Ensure packet redirect sending is disabledCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2 Ensure packet redirect sending is disabledCIS CentOS Linux 7 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

ARST-RT-000600 - The Arista BGP router must be configured to enable the Generalized TTL Security Mechanism (GTSM).DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000140 - The Cisco router must be configured to enforce approved authorizations for controlling the flow of management information within the device based on control policies.DISA Cisco IOS Router NDM STIG v3r8Cisco

ACCESS CONTROL

CISC-ND-000570 - The Cisco router must be configured to enforce password complexity by requiring that at least one uppercase character be used.DISA Cisco IOS Router NDM STIG v3r8Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000580 - The Cisco router must be configured to enforce password complexity by requiring that at least one lowercase character be used.DISA Cisco IOS Router NDM STIG v3r8Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000590 - The Cisco router must be configured to enforce password complexity by requiring that at least one numeric character be used.DISA Cisco IOS Router NDM STIG v3r8Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000720 - The Cisco router must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS Router NDM STIG v3r8Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001140 - The Cisco router must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.DISA Cisco IOS Router NDM STIG v3r8Cisco

ACCESS CONTROL

CISC-ND-001150 - The Cisco router must be configured to authenticate Network Time Protocol (NTP) sources using authentication with FIPS-compliant algorithms.DISA Cisco IOS Router NDM STIG v3r8Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-001260 - The Cisco router must be configured to generate audit records when successful/unsuccessful logon attempts occur.DISA Cisco IOS Router NDM STIG v3r8Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001410 - The Cisco router must be configured to back up the configuration when changes occur.DISA Cisco IOS Router NDM STIG v3r8Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-RT-000010 - The Cisco router must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.DISA Cisco IOS Router RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000050 - The Cisco router must be configured to enable routing protocol authentication using FIPS 198-1 algorithms with keys not exceeding 180 days of lifetime.DISA Cisco IOS Router RTR STIG v3r4Cisco

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

CISC-RT-000150 - The Cisco router must be configured to have Gratuitous ARP disabled on all external interfaces.DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000160 - The Cisco router must be configured to have IP directed broadcast disabled on all interfaces.DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000250 - The Cisco perimeter router must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA Cisco IOS Router RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000395 - The Cisco perimeter router must be configured to drop IPv6 packets containing a Destination Option header with invalid option type values.DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000396 - The Cisco perimeter router must be configured to drop IPv6 packets containing an extension header with the Endpoint Identification option.DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000620 - The Cisco MPLS router must be configured to have TTL Propagation disabled.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000630 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS Router RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000660 - The Cisco PE router providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.DISA Cisco IOS Router RTR STIG v3r4Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000780 - The Cisco PE router must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000950 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to use a loopback address as the source address when originating MSDP traffic.DISA Cisco IOS Router RTR STIG v3r4Cisco

CONTINGENCY PLANNING

JUEX-NM-000240 - The Juniper EX switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL

JUSX-AG-000057 - The Juniper SRX Services Gateway Firewall must be configured to support centralized management and configuration of the audit log.DISA Juniper SRX Services Gateway ALG v3r3Juniper

AUDIT AND ACCOUNTABILITY

JUSX-AG-000084 - The Juniper SRX Services Gateway Firewall must not be configured as an NTP server since providing this network service is unrelated to the role as a firewall.DISA Juniper SRX Services Gateway ALG v3r3Juniper

CONFIGURATION MANAGEMENT

JUSX-AG-000128 - The Juniper SRX Services Gateway Firewall must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).DISA Juniper SRX Services Gateway ALG v3r3Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-AG-000150 - The Juniper SRX Services Gateway Firewall must generate an alert that can be forwarded to, at a minimum, the ISSO and ISSM when DoS incidents are detected.DISA Juniper SRX Services Gateway ALG v3r3Juniper

SYSTEM AND INFORMATION INTEGRITY

JUSX-DM-000023 - The Juniper SRX Services Gateway must automatically generate a log event when accounts are enabled.DISA Juniper SRX Services Gateway NDM v3r3Juniper

ACCESS CONTROL

JUSX-DM-000024 - The Juniper SRX Services Gateway must generate an immediate alert message to the management console for account enabling actions.DISA Juniper SRX Services Gateway NDM v3r3Juniper

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

JUSX-DM-000044 - The Juniper SRX Services Gateway must generate log records when privileged commands are executed.DISA Juniper SRX Services Gateway NDM v3r3Juniper

AUDIT AND ACCOUNTABILITY

JUSX-DM-000113 - The Juniper SRX Services Gateway must ensure access to start a UNIX-level shell is restricted to only the root account.DISA Juniper SRX Services Gateway NDM v3r3Juniper

CONFIGURATION MANAGEMENT

JUSX-DM-000133 - For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by requiring at least one special character be used.DISA Juniper SRX Services Gateway NDM v3r3Juniper

IDENTIFICATION AND AUTHENTICATION

JUSX-IP-000005 - The Juniper Networks SRX Series Gateway IDPS must block outbound traffic containing known and unknown DoS attacks by ensuring that rules are applied to outbound communications traffic.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-IP-000026 - The Juniper Networks SRX Series Gateway IDPS must automatically install updates to signature definitions.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND INFORMATION INTEGRITY

JUSX-IP-000029 - The Juniper Networks SRX Series Gateway IDPS must send an immediate alert to, at a minimum, the Security Control Auditor (SCA) when malicious code is detected.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND INFORMATION INTEGRITY

JUSX-VN-000003 - The Juniper SRX Services Gateway VPN must renegotiate the IKE security association after 24 hours or less.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

JUSX-VN-000006 - The Juniper SRX Services Gateway VPN must use AES256 encryption for the Internet Key Exchange (IKE) proposal to protect the confidentiality of remote access sessions - IKE proposal to protect the confidentiality of remote access sessions.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

JUSX-VN-000012 - The Juniper SRX Services Gateway VPN must not accept certificates that have been revoked when using PKI for authentication.DISA Juniper SRX Services Gateway VPN v3r2Juniper

CONFIGURATION MANAGEMENT

JUSX-VN-000023 - The Juniper SRX Services Gateway VPN Internet Key Exchange (IKE) must be configured to use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network - IKE must use cryptography that is compliant with Suite B parameters when transporting classified traffic across an unclassified network.DISA Juniper SRX Services Gateway VPN v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

OS10-RTR-000630 - The Dell OS10 Router must be configured to have IP directed broadcast disabled on all interfaces.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION