DBN-6300 NDM Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 2 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
- RMF Control
- AC-2
- Severity
- H
- CCI
- CCI-000015
- Version
- DBNW-DM-000006
- Vuln IDs
-
- V-64975
- Rule IDs
-
- SV-79465r1_rule
Checks: C-65633r3_chk
Verify that the LDAP authentication server is configured correctly. Navigate to Settings >> Initial Configuration >> Authentication. Verify that the LDAP server entry is correct and that the button for "LDAP Based Authentication" is enabled. Verify that the "Native takes precedence" button is set to "Disabled". If the LDAP server entry is not present and enabled, and the "Native takes precedence" button is not set to "Disabled", this is a finding.
Fix: F-70915r3_fix
Navigate to Settings >> Initial Configuration >> Authentication. Enter the correct LDAP server entry. Press the button for "LDAP Based Authentication" so that it is enabled. If necessary, press the "Disabled" button for "Native takes precedence". Press the "Commit" button.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- DBNW-DM-000009
- Vuln IDs
-
- V-64983
- Rule IDs
-
- SV-79473r1_rule
Checks: C-65641r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account creation. Confirm the presence of a syslog message on the syslog server containing the information for successful account creation. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a successful account creation has just occurred is not there, this is a finding.
Fix: F-70923r2_fix
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account creation. Confirm the presence of a syslog message on the syslog server containing the information for successful account creation.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001403
- Version
- DBNW-DM-000010
- Vuln IDs
-
- V-64985
- Rule IDs
-
- SV-79475r1_rule
Checks: C-65643r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account modification. Confirm the presence of a syslog message on the syslog server containing the information for successful account modification. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a successful account modification has just occurred is not there, this is a finding.
Fix: F-70925r2_fix
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account modification. Confirm the presence of a syslog message on the syslog server containing the information for successful account modification.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DBNW-DM-000089
- Vuln IDs
-
- V-64987
- Rule IDs
-
- SV-79477r1_rule
Checks: C-65645r2_chk
Verify that the LDAP authentication server is configured correctly. Navigate to Settings >> Initial Configuration >> Authentication. Verify that the LDAP server entry is correct and the button for "LDAP Based Authentication" is enabled. Verify that the "Native takes precedence" button is set to "Disabled". If the LDAP server entry is not present and enabled, and the "Native takes precedence" button is not set to "Disabled", this is a finding.
Fix: F-70927r2_fix
Navigate to Settings >> Initial Configuration >> Authentication. Enter the correct LDAP server entry. Press the button for "LDAP Based Authentication" so that it is enabled. If necessary, press the "Disabled" button for "Native takes precedence". Press the "Commit" button.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001405
- Version
- DBNW-DM-000012
- Vuln IDs
-
- V-64989
- Rule IDs
-
- SV-79479r1_rule
Checks: C-65647r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account removal. Confirm the presence of a syslog message on the syslog server containing the information for successful account removal. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a successful account removal has just occurred is not there, this is a finding.
Fix: F-70929r3_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- DBNW-DM-000015
- Vuln IDs
-
- V-64991
- Rule IDs
-
- SV-79481r1_rule
Checks: C-65649r2_chk
To see if the system will lock out the user if three failed logon attempts occur within 15 minutes, attempt to log on as a user three times in succession and deliberately fail (by entering the wrong password). After the third attempt, the user will be locked out from retrying until the oldest attempt (by time) ages out past the 15-minute mark and then will be allowed to try again. If the user is not locked out after three failed logon attempts within 15 minutes, this is a finding.
Fix: F-70931r2_fix
Set a time-to-retry variable, as well as number of retries during that lockout timeout variable, within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": { "local": { "policies": { "passwordFail": { "enable": true, "threshold": 3, "windowSeconds": 60 }}}}}
- RMF Control
- AU-10
- Severity
- L
- CCI
- CCI-000166
- Version
- DBNW-DM-000021
- Vuln IDs
-
- V-64993
- Rule IDs
-
- SV-79483r1_rule
Checks: C-65651r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process any account function. Confirm the presence of a syslog message on the syslog server containing the information for whatever that account function represented. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information for the account action that took place is not present, this is a finding.
Fix: F-70933r2_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DBNW-DM-000132
- Vuln IDs
-
- V-64995
- Rule IDs
-
- SV-79485r1_rule
Checks: C-65653r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", that the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes"; the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console; and the items for any locally developed list of auditable events is checked. Following this verification, process an account removal. Confirm the presence of a syslog message on the syslog server containing the date and time of this last logon. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a logon has just occurred is not there, this is a finding.
Fix: F-70935r2_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- DBNW-DM-000023
- Vuln IDs
-
- V-64997
- Rule IDs
-
- SV-79487r1_rule
Checks: C-65655r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process any account function. Confirm the presence of a syslog message on the syslog server containing the information for whatever that account function represented. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information for the account action that took place is not present, this is a finding.
Fix: F-70937r2_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- L
- CCI
- CCI-000171
- Version
- DBNW-DM-000024
- Vuln IDs
-
- V-76927
- Rule IDs
-
- SV-91623r1_rule
Checks: C-76551r1_chk
Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories can be checked in accordance with the role assigned. For an administrator, the admin role should allow all categories to be checked for Audit Log, Syslog, and Audit Console. Log off, log on again, and attempt to repeat the process logged on as a "lesser" user that does not have privileges to configure audit. Attempt to modify the audit log categories. This should fail. Following this verification, if it is possible for a non-privileged user with no audit log modification privileges to modify log functions, this is a finding.
Fix: F-83623r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000025
- Vuln IDs
-
- V-76929
- Rule IDs
-
- SV-91625r1_rule
Checks: C-76553r1_chk
Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and that the Audit Configuration Categories can be checked in accordance with the role assigned. For an administrator, the admin role should allow all categories to be checked for Audit Log, Syslog, and Audit Console. Log off, log on again, and attempt to repeat the process logged on as a "lesser" user that does not have privileges to configure audit. Attempt to modify the audit log categories. This should fail. Following this verification, if it is possible for a non-privileged user with no audit log modification privileges to modify log functions, this is a finding.
Fix: F-83625r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-14
- Severity
- L
- CCI
- CCI-001464
- Version
- DBNW-DM-000026
- Vuln IDs
-
- V-76931
- Rule IDs
-
- SV-91627r1_rule
Checks: C-76555r1_chk
Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories can be checked in accordance with the role assigned. For an administrator, the admin role should allow all categories to be checked for Audit Log, Syslog, and Audit Console. Log off and log on to the system again. Examine the message at the syslog server. If there is no message, or no information in the message containing data showing the logon, this is a finding.
Fix: F-83627r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000130
- Version
- DBNW-DM-000027
- Vuln IDs
-
- V-76933
- Rule IDs
-
- SV-91629r1_rule
Checks: C-76557r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the DBN-6300 is not connected to the syslog server, this is a finding.
Fix: F-83629r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000131
- Version
- DBNW-DM-000028
- Vuln IDs
-
- V-76935
- Rule IDs
-
- SV-91631r1_rule
Checks: C-76559r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an auditable action. Confirm the presence of a syslog message on the syslog server containing date and time information for when the event occurred. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message for the event does not contain date and time information, this is a finding.
Fix: F-83631r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000132
- Version
- DBNW-DM-000029
- Vuln IDs
-
- V-76937
- Rule IDs
-
- SV-91633r1_rule
Checks: C-76561r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an auditable action. Confirm the presence of a syslog message on the syslog server containing information to establish where the event occurred. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message for the event does not contain information to establish where the event occurred, this is a finding.
Fix: F-83633r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000133
- Version
- DBNW-DM-000030
- Vuln IDs
-
- V-76939
- Rule IDs
-
- SV-91635r1_rule
Checks: C-76563r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an auditable action. Confirm the presence of a syslog message on the syslog server containing information to establish the source of events. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message for the event does not contain information to establish the source of events, this is a finding.
Fix: F-83635r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000134
- Version
- DBNW-DM-000031
- Vuln IDs
-
- V-76941
- Rule IDs
-
- SV-91637r1_rule
Checks: C-76565r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an auditable action. Confirm the presence of a syslog message on the syslog server containing information to establish the outcome of the event. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message for the event does not contain information to establish the outcome of the event, this is a finding.
Fix: F-83637r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-001487
- Version
- DBNW-DM-000032
- Vuln IDs
-
- V-76943
- Rule IDs
-
- SV-91639r1_rule
Checks: C-76567r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an auditable action. Confirm the presence of a syslog message on the syslog server containing information to establish the identity of any individual or process associated with the event. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message for the event does not contain information to establish the identity of any individual or process associated with the event, this is a finding.
Fix: F-83639r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000135
- Version
- DBNW-DM-000033
- Vuln IDs
-
- V-76945
- Rule IDs
-
- SV-91641r1_rule
Checks: C-76569r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an auditable action. Confirm the presence of a syslog message on the syslog server containing the full-text recording of privileged commands. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message for the event does not contain the full-text recording of privileged commands, this is a finding.
Fix: F-83641r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000159
- Version
- DBNW-DM-000036
- Vuln IDs
-
- V-76947
- Rule IDs
-
- SV-91643r1_rule
Checks: C-76571r1_chk
Verify the configuration of the NTP server. Navigate to Settings >> Initial Configuration >> Time. View the "Time" settings window. If an NTP server address is not configured, this is a finding.
Fix: F-83643r1_fix
Configure the NTP server on the device. The time difference is part of the NTP protocol and is not configurable. Navigate to Settings >> Initial Configuration >> Time. In the "Time" settings window, select the "NTP" button and enter the NTP server address. Click on "Commit".
- RMF Control
- AU-9
- Severity
- L
- CCI
- CCI-001348
- Version
- DBNW-DM-000043
- Vuln IDs
-
- V-76949
- Rule IDs
-
- SV-91645r1_rule
Checks: C-76573r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process a logon. Confirm the presence of a syslog message on the syslog server containing the date and time of this last logon. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a logon had just occurred is not there, this is a finding.
Fix: F-83645r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog.
- RMF Control
- AC-2
- Severity
- H
- CCI
- CCI-001358
- Version
- DBNW-DM-000049
- Vuln IDs
-
- V-76951
- Rule IDs
-
- SV-91647r1_rule
Checks: C-76575r2_chk
Verify that there is one local account configured on the DBN-6300. Navigate to Settings >> User Management. Verify that there is one account on the system and that this account has unrestricted privileges. If no local account is configured in this way, or more than one account is configured locally, this is a finding.
Fix: F-83647r1_fix
Verify that there is one local account configured on the DBN-6300. Navigate to Settings >> User Management. Verify that there is one account on the system, and that this account has unrestricted privileges. If there is more than one local account, delete the additional accounts by clicking on the trashcan icon on the far right of the account(s) in question, until all accounts are deleted except for one administrative account with unlimited privileges. If there is no local account with administrative or unlimited privileges, create one using the following steps: Navigate to Settings >> User Management >> Users. Click on the New User button. Enter a username for Username, a name (optional), a 15-character (minimum) complex password, and the role of either Admin or Unrestricted. After all entries are filled, click "Save".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000765
- Version
- DBNW-DM-000050
- Vuln IDs
-
- V-76953
- Rule IDs
-
- SV-91649r1_rule
Checks: C-76579r1_chk
Multifactor authentication is managed through the LDAP server. Verify that LDAP (remote authentication) is enabled. Navigate to Settings >> Initial Configuration >> Authentication. Verify that LDAP server information is correctly entered and enabled. Verify that "Native takes precedence" is disabled. If LDAP server is not connected, or if "Native takes precedence" is not disabled, this is a finding.
Fix: F-83649r1_fix
Configure the LDAP server to be connected correctly and disable "Native takes precedence". Navigate to Settings >> Initial Configuration >> Authentication. Enter the correct LDAP server information and press the "Enable" button. Press the "Native takes precedence" "Disable" button (if it is not already disabled).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000767
- Version
- DBNW-DM-000051
- Vuln IDs
-
- V-76955
- Rule IDs
-
- SV-91651r1_rule
Checks: C-76581r1_chk
Multifactor authentication is managed through the LDAP server. Verify that LDAP (remote authentication) is enabled. Navigate to Settings >> Initial Configuration >> Authentication. Verify that LDAP server information is correctly entered and enabled. Verify that "Native takes precedence" is disabled. If LDAP server is not connected, or if "Native takes precedence" is not disabled, this is a finding.
Fix: F-83651r1_fix
Configure the LDAP server to be connected correctly and disable "Native takes precedence". Navigate to Settings >> Initial Configuration >> Authentication. Enter the correct LDAP server information and press the "Enable" button. Press the "Native takes precedence" "Disable" button (if it is not already disabled).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- DBNW-DM-000053
- Vuln IDs
-
- V-76957
- Rule IDs
-
- SV-91653r1_rule
Checks: C-76583r1_chk
Verify SSL is configured to use SSL for the web management tool. Navigate to Settings >> Initial Configuration >> Security. If the check box for "Enforce secure communications (SSL) for user interface access" is not checked, this is a finding.
Fix: F-83653r1_fix
Enable SSL for use with the web management tool. Navigate to Settings >> Initial Configuration >> Security. Select the check box for "Enforce secure communications (SSL) for user interface access". Click on "Commit".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- DBNW-DM-000055
- Vuln IDs
-
- V-76959
- Rule IDs
-
- SV-91655r1_rule
Checks: C-76585r1_chk
Verify the minimum password length is set to "15". Navigate to Settings >> Initial Configuration >> Authentication. If the "Minimum User Password Length" is not set to "15", this is a finding.
Fix: F-83655r1_fix
Configure the minimum password length to "15". Navigate to Settings >> Initial Configuration >> Authentication. Enter "15" in the "Minimum User Password Length". Click on "Commit".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000200
- Version
- DBNW-DM-000056
- Vuln IDs
-
- V-76961
- Rule IDs
-
- SV-91657r1_rule
Checks: C-76587r1_chk
To see if the system prohibits password reuse attempt to change the users password deliberately reusing the last passwords used. The user should fail to update their password for the last five passwords that their account has used. If the user is able to reuse their password before using five different password, this is a finding.
Fix: F-83657r1_fix
Set a password-reuse variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordReuse": {"check": true,"numberToKeep": 5 }}}}}
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- DBNW-DM-000057
- Vuln IDs
-
- V-76963
- Rule IDs
-
- SV-91659r1_rule
Checks: C-76589r1_chk
To see if the system requires password complexity attempt to change your password to a non-conforming password. If the user is able to change their password without meeting the requirement, this is a finding.
Fix: F-83659r1_fix
Set the password-complexity variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordQuality": {"owasp": {"enable": true,"allowPassphrases": false }}}}}}
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- DBNW-DM-000058
- Vuln IDs
-
- V-76965
- Rule IDs
-
- SV-91661r1_rule
Checks: C-76591r1_chk
To see if the system requires password complexity attempt to change your password to a non-conforming password. If the user is able to change their password without meeting the requirement, this is a finding.
Fix: F-83661r1_fix
Set the password-complexity variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordQuality": {"owasp": {"enable": true,"allowPassphrases": false }}}}}}
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- DBNW-DM-000059
- Vuln IDs
-
- V-76967
- Rule IDs
-
- SV-91663r1_rule
Checks: C-76593r1_chk
To see if the system requires password complexity attempt to change your password to a non-conforming password. If the user is able to change their password without meeting the requirement, this is a finding.
Fix: F-83663r1_fix
Set the password-complexity variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordQuality": {"owasp": {"enable": true,"allowPassphrases": false }}}}}}
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001619
- Version
- DBNW-DM-000060
- Vuln IDs
-
- V-76969
- Rule IDs
-
- SV-91665r1_rule
Checks: C-76595r1_chk
To see if the system requires password complexity attempt to change your password to a non-conforming password. If the user is able to change their password without meeting the requirement, this is a finding.
Fix: F-83665r1_fix
Set the password-complexity variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordQuality": {"owasp": {"enable": true,"allowPassphrases": false }}}}}}
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000198
- Version
- DBNW-DM-000064
- Vuln IDs
-
- V-76971
- Rule IDs
-
- SV-91667r1_rule
Checks: C-76597r1_chk
To see if the system requires a minimum password lifetime attempt to change your password two times quickly. If the user is able to change their password the second time, this is a finding.
Fix: F-83667r1_fix
Set the password-minAge variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordReuse": {"check": true, "minAge": 3600 }}}}}
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000199
- Version
- DBNW-DM-000065
- Vuln IDs
-
- V-76973
- Rule IDs
-
- SV-91669r1_rule
Checks: C-76599r1_chk
To see if the system requires a maximum password lifetime attempt to login with a user who has had their password set longer then password lifetime setting. If a user is able to log in successfully, this is a finding.
Fix: F-83669r1_fix
Set the password-maxAge variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: reg set /sysconfig/auth/01 {"stores": {"local": {"policies": {"passwordExpire": {"maxAge": 216000,"action": "reject"}}}}}
- RMF Control
- SC-10
- Severity
- H
- CCI
- CCI-001133
- Version
- DBNW-DM-000071
- Vuln IDs
-
- V-76975
- Rule IDs
-
- SV-91671r1_rule
Checks: C-76601r1_chk
Verify administrator accounts are configured with a 10-minute timeout setting. Navigate to Settings >> Users. Click on the wrench for an existing user. View each user defined on the device since there is no setting for a global value. If a timeout value of "600" is not set for each administrator account configured on the device, this is a finding.
Fix: F-83671r1_fix
Configure administrator accounts with a timeout setting. Navigate to Settings >> Users. Click on the wrench for an existing user. In the "Edit User" popup box, enter a timeout value of "600". Click on "Commit".
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001314
- Version
- DBNW-DM-000077
- Vuln IDs
-
- V-76977
- Rule IDs
-
- SV-91673r1_rule
Checks: C-76603r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process any account function. Confirm the presence of a syslog message on the syslog server containing the information for whatever that account function represented. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information for the account action that took place is not present, this is a finding.
Fix: F-83673r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DBNW-DM-000078
- Vuln IDs
-
- V-76979
- Rule IDs
-
- SV-91675r1_rule
Checks: C-76605r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and that the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process any account function. Confirm the presence of a syslog message on the syslog server containing the information for whatever that account function represented. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information for the account action that took place is not present, this is a finding.
Fix: F-83675r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- DBNW-DM-000083
- Vuln IDs
-
- V-76981
- Rule IDs
-
- SV-91677r1_rule
Checks: C-76607r1_chk
Verify administrator accounts are configured with a 10 minute timeout setting. Navigate to Settings >> Users. Click on the wrench for an existing user. View each user defined on the device since there is no setting for a global value. If a timeout value of "600" is not set for each administrator account configured on the device, this is a finding.
Fix: F-83677r1_fix
Configure administrator accounts with a timeout setting. Navigate to Settings >> Users. Click on the wrench for an existing user. In the "Edit User" popup box, enter a timeout value of "600".
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-002130
- Version
- DBNW-DM-000087
- Vuln IDs
-
- V-76983
- Rule IDs
-
- SV-91679r1_rule
Checks: C-76609r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, enable an account. Confirm the presence of a syslog message on the syslog server containing the date and time of this last logon. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that an account has been enabled is not there, this is a finding.
Fix: F-83679r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002234
- Version
- DBNW-DM-000093
- Vuln IDs
-
- V-76985
- Rule IDs
-
- SV-91681r1_rule
Checks: C-76611r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process a privileged function. Confirm the presence of a syslog message on the syslog server containing the privileged function. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that the privileged function that just occurred is not there, this is a finding.
Fix: F-83681r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- L
- CCI
- CCI-001914
- Version
- DBNW-DM-000096
- Vuln IDs
-
- V-76987
- Rule IDs
-
- SV-91683r1_rule
Checks: C-76613r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are able to be selected based on selectable event criteria for Audit Log, Syslog, and Audit Console. If, after navigating to Settings >> Advanced >> Audit Log, there is no facility to change the auditing to be performed within the system log based on selectable event criteria, this is a finding.
Fix: F-83683r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-001891
- Version
- DBNW-DM-000100
- Vuln IDs
-
- V-76989
- Rule IDs
-
- SV-91685r1_rule
Checks: C-76615r1_chk
Verify the configuration of the NTP server. Navigate to Settings >> Initial Configuration >> Time. View the "Time" settings window. If an NTP server address is not configured, this is a finding.
Fix: F-83685r2_fix
Configure the NTP server on the device. The time difference is part of the NTP protocol and is not configurable. Navigate to Settings >> Initial Configuration >> Time. In the "Time" settings window, select the "NTP" button and enter the NTP server address. Click on "Commit".
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-002046
- Version
- DBNW-DM-000101
- Vuln IDs
-
- V-76991
- Rule IDs
-
- SV-91687r1_rule
Checks: C-76617r1_chk
Verify the configuration of the NTP server. Navigate to Settings >> Initial Configuration >> Time. View the "Time" settings window. If an NTP server address is not configured, this is a finding.
Fix: F-83687r1_fix
Configure the NTP server on the device. The time difference is part of the NTP protocol and is not configurable. Navigate to Settings >> Initial Configuration >> Time. In the "Time" settings window, select the "NTP" button and enter the NTP server address. Click on "Commit".
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-001890
- Version
- DBNW-DM-000103
- Vuln IDs
-
- V-76993
- Rule IDs
-
- SV-91689r1_rule
Checks: C-76619r1_chk
Verify the time zone is configured for "UTC". Navigate to Settings >> Initial Configuration >> Time. View the "Time Zone" box. If the Time Zone is not set to "UTC", this is a finding.
Fix: F-83689r1_fix
Configure the time zone to "UTC". Navigate to Settings >> Initial Configuration >> Time and click on "NTP". Click on the drop-down box next to the "Time Zone" label. Select "UTC" underneath the "Etc" category. Click on "Commit".
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-001889
- Version
- DBNW-DM-000104
- Vuln IDs
-
- V-76995
- Rule IDs
-
- SV-91691r1_rule
Checks: C-76621r1_chk
Verify the configuration of the NTP server. Navigate to Settings >> Initial Configuration >> Time. View the "Time" settings window. If an NTP server address is not configured, this is a finding.
Fix: F-83691r1_fix
Configure the NTP server on the device. The time difference is part of the NTP protocol and is not configurable. Navigate to Settings >> Initial Configuration >> Time. In the "Time" settings window, select the "NTP" button and enter the NTP server address. Click on "Commit".
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001814
- Version
- DBNW-DM-000108
- Vuln IDs
-
- V-76997
- Rule IDs
-
- SV-91693r1_rule
Checks: C-76623r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account removal. Confirm the presence of a syslog message on the syslog server containing the date and time of this last logon. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a logon just occurred is not there, this is a finding.
Fix: F-83693r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- DBNW-DM-000117
- Vuln IDs
-
- V-76999
- Rule IDs
-
- SV-91695r1_rule
Checks: C-76625r1_chk
Verify SSL is configured to use SSL for the web management tool. Navigate to Settings >> Initial Configuration >> Security. If the check box for "Enforce secure communications (SSL) for user interface access" is not checked, this is a finding.
Fix: F-83695r1_fix
Configure the User Interface (UI) web management tool to use HTTPS for communications. Navigate to Settings >> Initial Configuration >> Security. Select the check box for "Enforce secure communications (SSL) for user interface access". Click on "Commit".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-003123
- Version
- DBNW-DM-000118
- Vuln IDs
-
- V-77001
- Rule IDs
-
- SV-91697r1_rule
Checks: C-76627r1_chk
Verify SSL is configured to use SSL for the web management tool. Navigate to Settings >> Initial Configuration >> Security. If the check box for "Enforce secure communications (SSL) for user interface access" is not checked, this is a finding.
Fix: F-83697r1_fix
Configure the User Interface (UI) web management tool to use HTTPS for communications. Navigate to Settings >> Initial Configuration >> Security. Select the check box for "Enforce secure communications (SSL) for user interface access". Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000121
- Vuln IDs
-
- V-77003
- Rule IDs
-
- SV-91699r1_rule
Checks: C-76629r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account administrator privilege modification. Confirm the presence of a syslog message on the syslog server containing the account administrator privilege modification. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that an account administrator privilege modification has occurred is not there, this is a finding.
Fix: F-83699r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000122
- Vuln IDs
-
- V-77005
- Rule IDs
-
- SV-91701r1_rule
Checks: C-76631r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account administrator privilege modification. Confirm the presence of a syslog message on the syslog server containing the deletion of account administrator privileges. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the deletion of account administrator privileges is not there, this is a finding.
Fix: F-83701r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes". If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit". Verify that the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If any of the Configuration Categories are not checked, cycle the top buttons until every category is completely checked. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000123
- Vuln IDs
-
- V-77007
- Rule IDs
-
- SV-91703r1_rule
Checks: C-76633r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process an account administrator privilege modification. Confirm the presence of a syslog message on the syslog server containing information pertinent to successful or unsuccessful logon attempts. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing information pertinent to successful or unsuccessful logon attempts is not there, this is a finding.
Fix: F-83703r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000124
- Vuln IDs
-
- V-77009
- Rule IDs
-
- SV-91705r1_rule
Checks: C-76635r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process any kind of privileged activity or any type of system-level access. Confirm the presence of a syslog message on the syslog server containing information pertinent to any kind of privileged activity or any type of system-level access. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information pertinent to any kind of privileged activity or any type of system-level access that was processed is not there, this is a finding.
Fix: F-83705r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000125
- Vuln IDs
-
- V-77011
- Rule IDs
-
- SV-91707r1_rule
Checks: C-76637r2_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, process any function using administrator access. Confirm the presence of a syslog message on the syslog server containing information pertinent to an event using administrator access that was processed. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information pertinent to any kind of administrator access is not there, this is a finding.
Fix: F-83707r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and he Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000126
- Vuln IDs
-
- V-77013
- Rule IDs
-
- SV-91709r1_rule
Checks: C-76639r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, a user should log on from two different workstations. Confirm the presence of a syslog message on the syslog server containing logon information pertinent to logons from the same user from two different workstations. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information pertinent to a user logging on concurrently from two different workstations is not there, this is a finding.
Fix: F-83709r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- DBNW-DM-000127
- Vuln IDs
-
- V-77015
- Rule IDs
-
- SV-91711r1_rule
Checks: C-76641r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. Following this verification, execute four processes: account creation, account modification, account termination, and account disabling. Confirm the presence of a syslog message on the syslog server containing information pertinent to account creation, account modification, account termination, and account disabling. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing information pertinent to the account creation, account modification, account termination, and account disabling is not there, this is a finding.
Fix: F-83711r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- DBNW-DM-000128
- Vuln IDs
-
- V-77017
- Rule IDs
-
- SV-91713r1_rule
Checks: C-76643r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the DBN-6300 is not connected to the syslog server, this is a finding.
Fix: F-83713r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- DBNW-DM-000142
- Vuln IDs
-
- V-77019
- Rule IDs
-
- SV-91715r1_rule
Checks: C-76645r1_chk
Verify the DBN-6300 is connected to the syslog server. Navigate to Settings >> Advanced >> Syslog. Verify that the syslog services are set to "on", the syslog server information is valid, and the syslog server has connected. Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes"; the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console; and the items for any locally developed list of auditable events is checked. Following this verification, process any type of account management activity. Confirm the presence of a syslog message on the syslog server containing the information regarding the account management function that was used. If the DBN-6300 is not connected to the syslog server, or if the syslog server is connected but the message containing the information that a logon has just occurred is not there, this is a finding.
Fix: F-83715r1_fix
Configure the DBN-6300 to be connected to the syslog server. Also configure the DBN-6300 to include audit records in the syslog message feed. Navigate to Settings >> Advanced >> Syslog. Enter the syslog connection information (port and IP address) and push the "enabled" button for both "TCP" and "enable". Navigate to Settings >> Advanced >> Audit Log. Verify that the Audit Syslog, "Use System Syslog" button is set to "Yes" and the Audit Configuration Categories are all checked for Audit Log, Syslog, and Audit Console. If the "Use System Syslog" button is not set to "Yes", press the "Yes" button. Click on "Commit".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DBNW-DM-000134
- Vuln IDs
-
- V-77021
- Rule IDs
-
- SV-91717r1_rule
Checks: C-76647r1_chk
Verify that the LDAP authentication server is configured correctly. Navigate to Settings >> Initial Configuration >> Authentication. Verify that the LDAP server entry is correct and the button for "LDAP Based Authentication" is enabled. Verify that the "Native takes precedence" button is set to "Disabled". If the LDAP server entry is not present and enabled, and the "Native takes precedence" button is not set to "Disabled", this is a finding.
Fix: F-83717r1_fix
Navigate to Settings >> Initial Configuration >> Authentication. Enter the correct LDAP server entry. Press the button for "LDAP Based Authentication" so that it is enabled. If necessary, press the "Disabled" button for "Native takes precedence". Press the "Commit" button.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DBNW-DM-000141
- Vuln IDs
-
- V-77023
- Rule IDs
-
- SV-91719r1_rule
Checks: C-76649r1_chk
Verify that the Public Key Certificate is installed and has been obtained from an appropriate certificate policy through an approved service provider. Navigate to CLI and verify that there is a registry entry similar to below: Reg set /sysconfig/tls/trustedcas EOF (enter/paste certificate here) EOF If an entry is not found in the registry with the appropriate certificate, this is a finding.
Fix: F-83719r1_fix
Verify that the Public Key Certificate is installed and has been obtained from an appropriate certificate policy through an approved service provider. Set the trusted-ca variable within the DBN-6300 through the CLI. This value is set with the following registry entry in the CLI: Reg set /sysconfig/tls/trustedcas EOF (enter/paste certificate here) EOF