Arista Multilayer Switches used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
An XCCDF Rule
Description
This requires the use of secure protocols instead of their unsecured counterparts, such as SSH instead of telnet, SCP instead of FTP, and HTTPS instead of HTTP.
- ID
- SV-75327r1_rule
- Version
- AMLS-NM-000340
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the network device to use secure protocols instead of their unsecured counterparts.
Configuration Example:
Disable unsecure protocols.
configure