Skip to content

Arista Multilayer Switches used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.

An XCCDF Rule

Description

This requires the use of secure protocols instead of their unsecured counterparts, such as SSH instead of telnet, SCP instead of FTP, and HTTPS instead of HTTP.

ID
SV-75329r1_rule
Version
AMLS-NM-000350
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the network device to use secure protocols instead of their unsecured counterparts.

Configuration Example: 

Disable unsecure protocols.
configure