Cisco Secure Network Analytics (SNA) Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- CSNA-ND-000010
- Vuln IDs
-
- V-284853
- Rule IDs
-
- SV-284853r1212030_rule
Checks: C-89423r1212028_chk
Verify the Cisco SNA appliance is configured to limit the number of concurrent sessions to an organization-defined number for all administrator accounts. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Session Settings >> Maximum Number of Concurrent Sessions. If the Cisco SNA appliance is not configured to limit the number of concurrent sessions to an organization-defined number for each administrator account, this is a finding.
Fix: F-89328r1212029_fix
Configure the SNA appliance to limit the number of concurrent sessions to an organization-defined number for all administrator accounts and/or administrator account types. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Session Settings. Input Maximum Number of Concurrent Sessions. Apply Configuration.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- CSNA-ND-000100
- Vuln IDs
-
- V-284862
- Rule IDs
-
- SV-284862r1227142_rule
Checks: C-89432r1212032_chk
Verify the Cisco SNA is configured to assign appropriate user roles to authenticated users. This requirement may be verified by demonstrating users logging in with various privilege levels. The configuration may also be compared as shown below: Navigate to SNA Dashboard >> Configure >> User Management >> Users >> Select a User >> Actions.... Examine the assigned Data Role. If the Cisco SNA appliance does not enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level, this is a finding.
Fix: F-89337r1212033_fix
Configure the Cisco SNA appliance to assign appropriate user roles or access levels to authenticated users: Navigate to SNA Dashboard >> Configure >> User Management >> Create Dropdown (Top Right) >> Data Role. Assign Data Read/Write privileges for the role. Save. Navigate to Users >> Select a User >> Actions.... Assign an appropriate Data Role.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001368
- Version
- CSNA-ND-000110
- Vuln IDs
-
- V-284863
- Rule IDs
-
- SV-284863r1212037_rule
Checks: C-89433r1212035_chk
Review the Cisco SNA appliance Sysconfig configuration to determine if it enforces approved authorizations for controlling the flow of management information within the network device based on information flow control policies. Log in to the appliance console as sysadmin. Select Network >> Trusted Hosts. Verify only required trusted IPs/hosts are listed, including other SNA appliances. Note: The Trusted Hosts list acts as an access control list (ACL). If the Cisco SNA appliance does not enforce these approved authorizations, this is a finding.
Fix: F-89338r1212036_fix
Configure the Cisco SNA appliance to enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies. Log in to the appliance console as sysadmin. Select Network >> Trusted Hosts. Input only required trusted IPs/hosts, including other SNA appliances. Note: The Trusted Hosts list acts as an ACL.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- CSNA-ND-000120
- Vuln IDs
-
- V-284864
- Rule IDs
-
- SV-284864r1205360_rule
Checks: C-89434r1205358_chk
Review the Cisco SNA appliance configuration to verify it enforces the limit of three consecutive invalid logon attempts. Navigate to Cisco SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Session Settings >> Number of Unsuccessful Attempts and Duration of Lockout. If the Cisco SNA appliance is not configured to enforce the limit of three consecutive invalid logon attempts, this is a finding.
Fix: F-89339r1205359_fix
Configure the Cisco SNA appliance to enforce the limit of three consecutive invalid logon attempts during a 15-minute time period. Navigate to Cisco SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Session Settings. Input a number for "Number of Unsuccessful Attempts and Duration of Lockout". Apply the configuration.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- CSNA-ND-000130
- Vuln IDs
-
- V-284865
- Rule IDs
-
- SV-284865r1227148_rule
Checks: C-89435r1227146_chk
Determine if the Cisco SNA appliance is configured to present a DoW-approved banner that is formatted in accordance with DTM-08-060. Use the following verbiage for applications that can accommodate banners of 1300 characters: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." This is verified by navigating to the appliance login page where the banner should be displayed and accepted by clicking "Continue". If the DoW banner is not displayed, this is a finding.
Fix: F-89340r1227147_fix
Configure the Cisco SNA appliance to display the Standard Mandatory DoW Notice and Consent Banner before granting access to the device. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Opening Message. Enter the following text: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." Apply the configuration.
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000382
- Version
- CSNA-ND-000330
- Vuln IDs
-
- V-284884
- Rule IDs
-
- SV-284884r1212060_rule
Checks: C-89454r1212058_chk
Review the Cisco SNA appliance configuration to determine if it prohibits the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services. Navigate to Cisco SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> Appliance Tab >> SSH. Verify "Enable" is unchecked. Navigate to Network Services tab >> SNMP Agent. Verify "Enable" is unchecked if not needed by the organization. Navigate to Network Services tab >> Internet Proxy. Verify "Enable" is unchecked if not needed by the organization. Navigate to General Tab >> External Services. Verify "Enable" is unchecked if not needed by the organization. If any unnecessary or nonsecure functions are permitted, this is a finding.
Fix: F-89359r1212059_fix
Configure the Cisco SNA appliance to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services. Navigate to Cisco SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> Appliance Tab. Ensure "SSH" is unchecked. Navigate to Network Services tab >> SNMP Agent. Uncheck "Enable" if not needed by organization. Navigate to Network Services tab >> Internet Proxy. Uncheck "Enable" if not needed by organization. Navigate to General tab >> External Services. Uncheck "Enable" if not needed by organization. Click "Apply Settings".
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001358
- Version
- CSNA-ND-000340
- Vuln IDs
-
- V-284885
- Rule IDs
-
- SV-284885r1212063_rule
Checks: C-89455r1212061_chk
Review the Cisco SNA appliance configuration to determine if an account of last resort is configured. Verify the username and password for the account of last resort is contained within a sealed envelope and kept in a safe. Navigate to Cisco SNA Dashboard >> Configure >> User Management >> Users >> Select Account >> Actions... >> Edit. The authentication service should only be "local" for the "admin" account. Note: AAA centralized accounts are represented in this menu for role assignment, but cannot be logged into locally. If one local account does not exist for use as the account of last resort, this is a finding.
Fix: F-89360r1212062_fix
Configure the Cisco SNA appliance to use an account of last resort. Verify the username and password for the account of last resort is contained within a sealed envelope and kept in a safe. Navigate to Cisco SNA Dashboard >> Configure >> User Management >> Users >> Select Account >> Actions... >> Edit. The authentication service should only be "local" for the "admin" account. Delete all others. Note: AAA centralized accounts are represented in this menu for role assignment but cannot be logged into locally.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000765
- Version
- CSNA-ND-000350
- Vuln IDs
-
- V-284886
- Rule IDs
-
- SV-284886r1227140_rule
Checks: C-89456r1227138_chk
Verify the Cisco SNA appliance is configured to use DoW PKI as MFA for interactive logins. Navigate to the login page and select Single Sign-on (SSO). At the SAML Identity Provider (IdP) login page, enter the certificate with PIN as managed by middleware, (e.g., ActivClient). Note: The MFA requirement is met by the SSO server and will require coordination with the server's administrator. If the Cisco SNA appliance is not configured to use SSO with DoW PKI as MFA for interactive logins, this is a finding. If the PKI authenticated user is not mapped to the effective local user account this is a finding.
Fix: F-89361r1227139_fix
Configure the network device to use SSO with DoW PKI as MFA for interactive logins. A. Prepare for Configuration. 1. The following information is required to configure SSO: - The IdP URL must use the fully qualified domain name or IPv4 address. - If the IdP URL starts with HTTPS, download the CA certificate. 2. Certificate Requirements: If the URL for downloading the IdP URL starts with HTTPS, confirm the certificate was added to the appliance Trust Stores. B. Configure the Service Provider. 1. Navigate to the management console webpage (SMC). 2. Log in as an admin with sufficient privileges. 3. Select Configure >> User Management. 4. Select Create (Dropdown) >> Authentication Service >> SSO. 5. Select IdP Type (Dropdown) >> Microsoft ADFS. 6. Enter the URL to download the IdP's configuration file. Requirements: Enter the fully qualified domain name or IP address. Alternatively, upload an Identity Provider Metadata XML File. 7. Select "Disable Requested Authentication Context". 8. Select Name Identifier Format >> Transient (if following schema note below). Otherwise, configure according to local format. 9. Add a Login Screen Label relevant to local configurations. 10. Select "Save". 11. When redirected to the Authentication and Authorization tab, it may take up to five minutes to apply changes and SSO Status to become "Ready". 12. Select Actions >> Enable SSO. C. Configure ADFS according to local procedure to add the Relying Party Trust. Note: For ADFS configuration, create and modify the following Claim Issuance Policy Custom Rule: c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:2.0:nameid-format:transient", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/namequalifier"] = "http://YOURADFSFQDN./adfs/com/adfs/service/trust", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/spnamequalifier"] = "https://YOURSNAFQDN/fedlet"); D. Add an SSO User. 1. Log in to the SMC Web UI. 2. Select Configure >> User Management >> Users >> Create User. 3. Complete the fields to create a new user. - Authentication Service: Select SSO. - User Name: Enter the first part of the email address for the IdP account. Ensure the ID is identical to the one that will be used for SSO at login. For example, for name@email.com, enter name in this field. 4. Click "Save". 5. Confirm the SSO User is shown in User Management.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- CSNA-ND-000380
- Vuln IDs
-
- V-284887
- Rule IDs
-
- SV-284887r1212067_rule
Checks: C-89457r1212066_chk
Review the Password Policy configuration of the Cisco SNA appliance. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy. Verify the "Password Minimum Character Length" is 15 or greater. If the Cisco SNA appliance is not configured to enforce a minimum 15-character password length for local accounts, this is a finding.
Fix: F-89362r1205428_fix
Configure the Cisco SNA appliance to enforce a minimum 15-character password length. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Password Minimum Character Length. Set to "15" or greater. Click "Apply Settings".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- CSNA-ND-000390
- Vuln IDs
-
- V-284888
- Rule IDs
-
- SV-284888r1212069_rule
Checks: C-89458r1212068_chk
Review the Password Policy configuration of the Cisco SNA appliance. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Number of Upper Case Letters in Password. Verify the number is one or greater. If the Cisco SNA appliance is not configured to require that at least one uppercase character be used in local account passwords, this is a finding.
Fix: F-89363r1205431_fix
Configure the Cisco SNA appliance to enforce password complexity by requiring at least one uppercase character be used. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Number of Upper Case Letters in Password. Set to "1" or greater. Click "Apply Settings".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- CSNA-ND-000400
- Vuln IDs
-
- V-284889
- Rule IDs
-
- SV-284889r1212071_rule
Checks: C-89459r1212070_chk
Review the Password Policy configuration of the Cisco SNA appliance. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Number of Lower Case Letters in Password. Verify the number is "1" or greater. If the Cisco SNA appliance is not configured to require at least one lowercase character be used in local account passwords, this is a finding.
Fix: F-89364r1205434_fix
Configure the Cisco SNA appliance to enforce password complexity by requiring at least one lowercase character be used. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Number of Lower Case Letters in Password. Set to "1" or greater. Click "Apply Settings".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- CSNA-ND-000410
- Vuln IDs
-
- V-284890
- Rule IDs
-
- SV-284890r1212073_rule
Checks: C-89460r1212072_chk
Review the Password Policy configuration of the Cisco SNA appliance. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Numbers in Password. Verify the number is "1" or greater. If the Cisco SNA appliance is not configured to require that at least one numeric character be used in local account passwords, this is a finding.
Fix: F-89365r1205437_fix
Configure the Cisco SNA appliance to enforce password complexity by requiring at least one numeric character be used. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Numbers in Password. Set to "1" or greater. Click "Apply Settings".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- CSNA-ND-000420
- Vuln IDs
-
- V-284891
- Rule IDs
-
- SV-284891r1212075_rule
Checks: C-89461r1212074_chk
Review the Password Policy configuration of the Cisco SNA appliance. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Number of Symbols in Password. Verify the number is "1" or greater. If the Cisco SNA appliance is not configured to require that at least one special character be used in local account passwords, this is a finding.
Fix: F-89366r1205440_fix
Configure the Cisco SNA appliance to enforce password complexity by requiring at least one special character be used. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Minimum Numbers of Symbols in Password. Set to "1" or greater. Click "Apply Settings".
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- CSNA-ND-000430
- Vuln IDs
-
- V-284892
- Rule IDs
-
- SV-284892r1212078_rule
Checks: C-89462r1212076_chk
Review the Password Policy configuration of the Cisco SNA appliance. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Number of Characters Different From Previous Password. Verify the number is "8" or greater. If the Cisco SNA appliance does not require that when a local account password is changed, the characters are changed in at least eight of the positions within the password, this is a finding.
Fix: F-89367r1212077_fix
Configure the Cisco SNA appliance to require that when a password is changed, the characters are changed in at least eight of the positions within the password. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy >> Number of Characters Different From Previous Password. Set to "8" or greater. Click "Apply Settings".
- RMF Control
- IA-7
- Severity
- H
- CCI
- CCI-000803
- Version
- CSNA-ND-000490
- Vuln IDs
-
- V-284896
- Rule IDs
-
- SV-284896r1227141_rule
Checks: C-89466r1212081_chk
Verify the Cisco SNA appliance is configured to use FIPS 140-3-approved algorithms for authentication to a cryptographic module by restricting encryption to Compliance Mode. Navigate to SNA Dashboard >> Configure >> Central Management >> (Appliance) Actions >> Edit Appliance Configuration >> General tab >> Compliance Mode. Verify "Enable FIPS Encryption Libraries" is checked at a minimum. If the Cisco SNA Appliance does not use FIPS-validated MAC to protect the integrity of nonlocal maintenance and diagnostic communications, this is a finding.
Fix: F-89371r1205455_fix
Configure the network device to use FIPS-validated MAC to protect the integrity of nonlocal maintenance and diagnostic communications. Navigate to SNA Dashboard >> Configure >> Central Management >> (Appliance) Actions >> Edit Appliance Configuration >> General tab >> Compliance Mode. Read the warnings and ensure all prerequisites are met. Then, check the boxes and type the requested number sequence to confirm. Select "Enable FIPS Encryption Libraries" and "Enable Common Criteria Encryption Libraries" for the most restrictive combination. Click "Apply Settings". Note: Review the Help Menu and configuration guides to ensure the configuration has met all prerequisites prior to enabling restricted libraries.
- RMF Control
- SC-10
- Severity
- H
- CCI
- CCI-001133
- Version
- CSNA-ND-000500
- Vuln IDs
-
- V-284897
- Rule IDs
-
- SV-284897r1212085_rule
Checks: C-89467r1212083_chk
Determine if the Cisco SNA appliance is configured to terminate the connection associated with a device management session after five minutes of inactivity. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Protected Sessions Time-Out >> Log Out User Due To Inactivity After this Many Minutes. Verify the number is "5" or fewer. If the Cisco SNA appliance does not terminate the connection associated with a device management session at the end of the session or after five minutes of inactivity, this is a finding. Verify the Cisco SNA appliance is configured to close admin sessions after eight hours or fewer. Navigate to Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Protected Sessions Time-Out >> Request User Re-authentication For Administrator-only Functions After This Many Minutes. Verify the number is "480" or less. If the Cisco SNA appliance is not configured to close admin sessions after eight hours or less, this is a finding.
Fix: F-89372r1212084_fix
Configure the Cisco SNA appliance to terminate the connection associated with a device management session after five minutes of inactivity. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Protected Sessions Time-Out >> Log Out User Due To Inactivity After this Many Minutes. Set to 5 or fewer. Click "Apply Settings". Configure the Cisco SNA appliance to close admin sessions after eight hours or less. Navigate to Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General>> Protected Sessions Time-Out >> Request User Re-authentication For Administrator-only Functions After This Many Minutes. Set to "480" or fewer. Click "Apply Settings".
- RMF Control
- SC-28
- Severity
- M
- CCI
- CCI-001199
- Version
- CSNA-ND-000540
- Vuln IDs
-
- V-284901
- Rule IDs
-
- SV-284901r1227145_rule
Checks: C-89471r1227144_chk
Review the Cisco SNA appliance configuration to verify information at rest (i.e., backup configuration file) are encrypted. Navigate to SNA Dashboard >> Configure >> Central Management >> (Appliance) Actions >> Edit Appliance Configuration >> General tab >> Backup Configuration Encryption. Verify "Enable Encryption" is checked and "Password" has been set. Note: The encryption method is automatically set to AES256-GCM for this feature. If the information at rest (i.e., backup configuration file) is not encrypted using a DoW-accepted algorithm, this is a finding.
Fix: F-89376r1212090_fix
Configure the SNA appliance to encrypt information at rest by enabling the "Backup Configuration Encryption" feature. Navigate to SNA Dashboard >> Configure >> Central Management >> (Appliance) Actions >> Edit Appliance Configuration >> General tab >> Backup Configuration Encryption. Check "Enable Encryption" and enter a password in the "Password" boxes. Click "Apply Settings". Note: The encryption method is automatically set to AES256-GCM for this feature.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001858
- Version
- CSNA-ND-000640
- Vuln IDs
-
- V-284910
- Rule IDs
-
- SV-284910r1212103_rule
Checks: C-89480r1212101_chk
Determine if the Cisco SNA appliance is configured to generate an immediate alert of all audit failure events requiring real-time alerts. Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Edit Appliance Configuration >> General Tab >> SMTP Configuration. Verify an SMTP server is configured (e.g., port, From Email, User Name, Password and Encryption Type). Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Edit Appliance Configuration >> General Tab >> DODIN Notifications. Verify "DODIN Notifications" is "Enabled" and sent to an appropriate email address. If an immediate alert of all audit failure events requiring real-time alerts is not generated, this is a finding.
Fix: F-89385r1212102_fix
Configure the Cisco SNA appliance to generate an immediate real-time alert of all audit failure events requiring real-time alerts. Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Edit Appliance Configuration >> General Tab >> SMTP Configuration. Input the SMTP server settings (e.g., SMTP Server, Port, From Email, User Name, Password and Encryption Type). Select "Apply Settings". Note: The encryption type must be SMTPS or STARTTLS. Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Edit Appliance Configuration >> General Tab >> DODIN Notifications. Click "Enable DODIN Notifications" and set the appropriate email address. Select "Apply Settings".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- CSNA-ND-000700
- Vuln IDs
-
- V-284916
- Rule IDs
-
- SV-284916r1212111_rule
Checks: C-89486r1212109_chk
Review the Cisco SNA appliance configuration to verify SNMP messages are authenticated using a FIPS-validated Keyed-HMAC. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> Network Services. Verify "SNMP Agent" is "Enabled". Verify "SNMP Versions" is "3". Verify "Authentication Protocol" is set to "HMAC192_SHA256" or better. If the Cisco SNA appliance is not configured to authenticate SNMP messages using a FIPS-validated HMAC, this is a finding.
Fix: F-89391r1212110_fix
Configure the Cisco SNA appliance to authenticate SNMP messages using a FIPS-validated Keyed-HMAC. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> Network Services. Set "SNMP Agent" to "Enabled". Set "SNMP Versions" to "3". Set "Authentication Protocol" to "HMAC192_SHA256" or better. Select "Apply Settings".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- CSNA-ND-000710
- Vuln IDs
-
- V-284917
- Rule IDs
-
- SV-284917r1212114_rule
Checks: C-89487r1212112_chk
Review the Cisco SNA appliance configuration to determine if the network device authenticates NTP endpoints before establishing a local, remote, or network connection using authentication that is cryptographically based. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> Network Services >> NTP Server. Verify a key symbol appears next to each NTP Server Entry. If the Cisco SNA appliance does not authenticate Network Time Protocol sources using authentication that is cryptographically based, this is a finding.
Fix: F-89392r1212113_fix
Configure the Cisco SNA appliance to authenticate NTP sources using authentication that is cryptographically based. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> Network Services >> NTP Server >> Actions >> Authenticate Connection. Enter a Key ID and Key Value. Apply Authentication.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- CSNA-ND-000770
- Vuln IDs
-
- V-284919
- Rule IDs
-
- SV-284919r1212118_rule
Checks: C-89489r1212116_chk
Verify software updates are consistently applied to the Cisco SNA appliance within 30 days unless the time period is directed by an authoritative source. Navigate to SNA Dashboard >> Configure >> Central Management >> Update Manager. View the "Installed Version" for each appliance. Compare each one to the authoritative source version. If the Cisco SNA appliance administrator does not install security-relevant updates within 30 days unless the time period is directed by an authoritative source, this is a finding.
Fix: F-89394r1212117_fix
Ensure patches are consistently applied to the Cisco SNA appliance within the time allowed. Navigate to SNA Dashboard >> Configure >> Central Management >> Update Manager >> Upload Update File (previously downloaded from Cisco Software Central) >> Select Appliance >> Actions... >> Install Update. Note: The SNA Manager should always be updated first to avoid versioning conflicts.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- CSNA-ND-000820
- Vuln IDs
-
- V-284924
- Rule IDs
-
- SV-284924r1212125_rule
Checks: C-89494r1212123_chk
Verify the Cisco SNA appliance generates audit records for modification of critical system files. Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Support >> Audit Logs. Verify AIDE logs are being produced. If the network device does not generate audit records for modification of critical system files, this is a finding.
Fix: F-89399r1212124_fix
Configure the Cisco SNA appliance to generate audit records for modification of critical system files. Navigate to SNA Dashboard >> Configure >> Central Management >> (Appliance) Actions >> Edit Appliance Configuration >> Appliance Tab. Enable AIDE checkbox. Click "Apply Settings".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- CSNA-ND-000870
- Vuln IDs
-
- V-284928
- Rule IDs
-
- SV-284928r1212129_rule
Checks: C-89498r1205550_chk
Verify HTTP/1.x downgrading is disabled. Navigate to Sysadmin Console >> Network >> HTTP Version >> Select >> Yes to Warning >> OK. If the message displayed states "There are no changes to HTTP/2 settings.", then HTTP/1.x has been disabled. If the HTTP/1.x downgrading is enabled, this is a finding.
Fix: F-89403r1205551_fix
Configure the Cisco SNA Appliance to use HTTP/2. Navigate to Sysadmin Console >> Network >> HTTP Version >> Select >> Yes to Warning >> OK.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000370
- Version
- CSNA-ND-000900
- Vuln IDs
-
- V-284931
- Rule IDs
-
- SV-284931r1212136_rule
Checks: C-89500r1212134_chk
Review the Cisco SNA appliance configuration to verify the device is configured to use at least two authentication servers or a single sign-on (SSO) service as primary source for authentication. Navigate to SNA Dashboard >> Configure >> User Management >> Authentication and Authorization Tab >> Select a Service >> Actions... >> Edit. Observe whether multiple addresses have been configured. Note: It is expected that an SSO using SAML will employ redundant/load-balanced servers on the service side. There is no configuration for multiple SSO services. If the Cisco SNA appliance is not configured to use at least two authentication servers or an SSO service for the purpose of authenticating users prior to granting administrative access, this is a finding.
Fix: F-89405r1212135_fix
Configure the SNA appliance to use at least two authentication servers or an SSO service. TACACS+/RADIUS/LDAP Configuration: Navigate to SNA Dashboard >> Configure >> User Management >> Authentication and Authorization Tab >> Create (dropdown) >> Authentication Service. Select Type (e.g., TACACS+, RADIUS, LDAP). Input "Name" for service and "Add New" Server Information for each server of that service type. Save. Navigate to Create (dropdown) >> User. Input User Name, Authentication service (previously created), Role Settings. Save. Apply Configuration. OR SSO Configuration: A. Prepare for Configuration. 1. The following information is required to configure SSO: -The Identity Provider (IdP) URL must use the fully qualified domain name or IPv4 address. - If the IdP URL starts with HTTPS, download the certificate authority (CA) certificate. 2. Certificate Requirements: If the URL for downloading the IDP URL starts with HTTPS, confirm the certificate is added to the appliance Trust Stores. B. Configure the Service Provider. 1. Navigate to the management console webpage (SMC). 2. Log in as an admin with sufficient privileges. 3. Select Configure >> User Management. 4. Select Create (Dropdown) >> Authentication Service >> SSO. 5. Select IdP Type (Dropdown) >> Microsoft ADFS. 6. Enter the URL to download the IdP's configuration file. Requirements: Enter the fully qualified domain name or IP address. Alternatively, upload an Identity Provider Metadata XML File. 7. Select "Disable Requested Authentication Context". 8. Select Name Identifier Format >> Transient (if following schema note below). Otherwise configure according to local format. 9. Add a Login Screen Label relevant to local configurations. 10. Select "Save". 11. When redirected to the Authentication and Authorization tab, it may take up to five minutes to apply changes and SSO Status to become "Ready". 12. Select Actions >> Enable SSO. C. Configure ADFS according to local procedure to add the Relying Party Trust. Note: For ADFS configuration, create and modify the following Claim Issuance Policy Custom Rule: c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:2.0:nameid-format:transient", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/namequalifier"] = "http://YOURADFSFQDN./adfs/com/adfs/service/trust", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/spnamequalifier"] = "https://YOURSNAFQDN/fedlet"); D. Add an SSO User. 1. Log in to the SMC Web UI. 2. Select Configure >> User Management >> Users >> Create User. 3. Complete the fields to create a new user. -Authentication Service: Select SSO. - User Name: Enter the first part of the email address for the IdP account. Ensure the ID is identical to the one that will be used for SSO at login. For example, for name@email.com, enter name in this field. 4. Click "Save". 5. Confirm the SSO User is shown in User Management.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- CSNA-ND-000930
- Vuln IDs
-
- V-284934
- Rule IDs
-
- SV-284934r1227151_rule
Checks: C-89503r1227149_chk
Determine if the Cisco SNA appliance obtains public key certificates from an appropriate certificate policy through an approved service provider. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Configuration >> Appliance Tab >> SSL/TLS Appliance Identity. Review the TLS certificate to determine if it is issued by a DoW CA. If the Cisco SNA appliance does not obtain its public key certificates from an appropriate certificate policy through an approved service provider, this is a finding.
Fix: F-89408r1227150_fix
Configure the network device to obtain its public key certificates from an appropriate certificate policy through an approved service provider. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Edit Configuration >> Appliance Tab >> SSL/TLS Appliance Identity >> Update Identity >> Generate CSR. Input RSA Key Length. Download CSR >> Submit CSR to DoW CA >> Click Replace Identity >> Apply Settings. For further details review the SNA SSL/TLS Certificates Guide: https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/certificates/7_5_3_SSL_TLS_Certificates_for_Managed_Appliances_Guide_DV_1_0.pdf.
- RMF Control
- AU-4
- Severity
- H
- CCI
- CCI-001851
- Version
- CSNA-ND-000940
- Vuln IDs
-
- V-284935
- Rule IDs
-
- SV-284935r1212214_rule
Checks: C-89504r1212142_chk
Verify the Cisco SNA appliance is configured to send log data to at least one central log server. Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Edit Appliance Configuration >> Network Services tab >> Audit Log Destination (Syslog over TLS). Verify one syslog server is configured. If the Cisco SNA appliance is not configured to send log data to at least one central log server, this is a finding.
Fix: F-89409r1212143_fix
Configure the Cisco SNA appliance to send log data to at least one central log server. Repeat these steps for each Syslog Server needed. Navigate to SNA Dashboard >> Configure >> Central Management >> Actions... >> Edit Appliance Configuration >> Network Services tab >> Audit Log Destination (Syslog over TLS) >> Add New. Input a Server Name or IP Address, Destination Port, and Certificate Revocation Mode. Apply Settings.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- CSNA-ND-000950
- Vuln IDs
-
- V-284936
- Rule IDs
-
- SV-284936r1212147_rule
Checks: C-89505r1212145_chk
Verify the Cisco SNA appliance is running an operating system release that is currently supported by the vendor. SNA Dashboard >> Configure >> Central Management >> Update Manager. View the "Installed Version" for each appliance. Compare to the supported versions on the vendor website. If the Cisco SNA appliance is not a version supported by the vendor, this is a finding.
Fix: F-89410r1212146_fix
Upgrade the Cisco SNA appliance to an operating system that is supported by the vendor. Navigate to SNA Dashboard >> Configure >> Central Management >> Update Manager >> Upload Update File (previously downloaded from Cisco Software Central) >> Select Appliance >> Actions... >> Install Update.
- RMF Control
- Severity
- M
- CCI
- CCI-004046
- Version
- CSNA-ND-000970
- Vuln IDs
-
- V-284937
- Rule IDs
-
- SV-284937r1212207_rule
Checks: C-89506r1212206_chk
Verify the network device is configured to implement MFA for local, network, and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access. Navigate to the login page, then select Single Sign-on (SSO). At the SAML IdP login page, enter a certificate and pin (as managed by middleware such as ActivClient) when prompted. Note: The MFA requirement is met by the SSO server and will require coordination with that server's administrator. If the Cisco SNA appliance is not configured to implement multifactor authentication for local, network, and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access, this is a finding.
Fix: F-89411r1212149_fix
Configure the Cisco SNA appliance to implement multifactor authentication for local, network, and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access. A. Prepare for Configuration. 1. The following information is required to configure SSO: -The Identity Provider (IdP) URL must use the fully qualified domain name or IPv4 address. - If the IdP URL starts with HTTPS, download the certificate authority (CA) certificate. 2. Certificate Requirements: If the URL for downloading the IDP URL starts with HTTPS, confirm the certificate is added to the appliance Trust Stores. B. Configure the Service Provider. 1. Navigate to the SMC. 2. Log in as an admin with sufficient privileges. 3. Select Configure >> User Management. 4. Select Create (Dropdown) >> Authentication Service >> SSO. 5. Select IdentityProvider (IdP) Type (Dropdown) >> Microsoft ADFS. 6. Enter the URL where the Identity Provider's configuration file can be downloaded. Requirements: Enter the fully qualified domain name or IP address. Alternatively, upload an Identity Provider Metadata XML File. 7. Select "Disable Requested Authentication Context". 8. Select Name Identifier Format >> Transient (if following schema note below). Otherwise, configure according to local format. 9. Add a Login Screen Label relevant to local configurations. 10. Select "Save". 11. When redirected to the Authentication and Authorization tab, it may take up to five minutes to apply changes and SSO Status to become "Ready". 12. Select Actions >> Enable SSO. C. Configure ADFS according to local procedure to add the Relying Party Trust. Note: For ADFS configuration, create and modify the following Claim Issuance Policy Custom Rule: c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:2.0:nameid-format:transient", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/namequalifier"] = "http://YOURADFSFQDN./adfs/com/adfs/service/trust", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/spnamequalifier"] = "https://YOURSNAFQDN/fedlet"); D. Add an SSO User. 1. Log in to the SMC Web UI. 2. Select Configure >> User Management >> Users >> Create User. 3. Complete the fields to create a new user. For compliance, configure the user as follows: Authentication Service: Select SSO. User Name: Enter the first part of the email address for the IdP account. Make sure the ID is identical to the one that will be used for SSO at login. For example, for name@email.com, enter "name" in this field. 4. Click "Save". 5. Confirm the SSO User is shown in User Management.
- RMF Control
- Severity
- M
- CCI
- CCI-004064
- Version
- CSNA-ND-001000
- Vuln IDs
-
- V-284939
- Rule IDs
-
- SV-284939r1212154_rule
Checks: C-89508r1212152_chk
Verify the Cisco SNA appliance is configured to allow user selection of long passwords and passphrases, including spaces and all printable characters. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy. Verify the "Maximum Number of Characters in Password" is greater than or equal to "32" (up to 256). Verify the "Minimum Number of Characters in Password" is greater than or equal to "15". If the Cisco SNA appliance is not configured to allow user selection of long passwords and passphrases, including spaces and all printable characters, this is a finding.
Fix: F-89413r1212153_fix
Configure the Cisco SNA appliance to allow user selection of long passwords and passphrases, including spaces and all printable characters. Navigate to SNA Dashboard >> Central Management >> Inventory >> Actions... >> Edit Appliance Configuration >> General >> Password Policy. Verify the "Maximum Number of Characters in Password" is greater than or equal to "32" (up to 256). Verify the "Minimum Number of Characters in Password" is greater than or equal to "15". Apply Settings.
- RMF Control
- Severity
- M
- CCI
- CCI-004068
- Version
- CSNA-ND-001010
- Vuln IDs
-
- V-284940
- Rule IDs
-
- SV-284940r1212209_rule
Checks: C-89509r1212155_chk
Verify the Cisco SNA appliance is configured to implement certificate revocation checking to support path discovery and validation. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Network Services >> Audit Log Destination (Syslog Over TLS). Verify "Certificate Revocation" set to "Hard Fail" for servers. Note that other forms of public key authentication (inter-device HTTPS, SAML, etc.) automatically perform certificate checking without additional configuration. If the Cisco SNA appliance is not configured to implement certificate revocation checking to support path discovery and validation, this is a finding.
Fix: F-89414r1212208_fix
Configure the Cisco SNA appliance to implement certificate revocation checking to support path discovery and validation using certificate revocation lists (CRLs), or Online Certificate Status Protocol (OCSP). Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> Network Services >> Audit Log Destination (Syslog Over TLS) >> Actions... >> Edit. Select "Hard Fail" for "Certificate Revocation". Note: Other forms of public key authentication (inter-device HTTPS, SAML, etc.) automatically perform certificate checking without additional configuration.
- RMF Control
- Severity
- M
- CCI
- CCI-004909
- Version
- CSNA-ND-001030
- Vuln IDs
-
- V-284942
- Rule IDs
-
- SV-284942r1212160_rule
Checks: C-89511r1212159_chk
Verify the Cisco SNA appliance is configured to include only approved trust anchors in trust stores or certificate stores managed by the organization. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> General >> Trust Store. Verify only approved certificates and Certificate Authorities (CAs) are present. If the Cisco SNA appliance is not configured to include only approved trust anchors in trust stores or certificate stores managed by the organization, this is a finding.
Fix: F-89416r1205591_fix
Configure the network device to include only approved trust anchors in trust stores or certificate stores managed by the organization. Navigate to SNA Dashboard >> Configure >> Central Management >> Inventory >> Actions... >> General >> Trust Store. Delete any untrusted certificates. Note: Ensure all appliance certificates had their self-signed certificates replaced and are trusted in each other's store.