STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Cisco NX OS Switch NDM Security Technical Implementation Guide

V-220501

CAT II (Medium)

The Cisco switch must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.

Rule ID

SV-220501r961506_rule

STIG

Cisco NX OS Switch NDM Security Technical Implementation Guide

Version

V3R6

CCIs

CCI-000068

Discussion

Without the strong encryption that is provided by the SNMP Version 3 User-based Security Model (USM), an unauthorized user can gain access to network management information that can be used to create a network outage.

Check Content

Review the Cisco switch configuration to verify that it is compliant with this requirement as shown in the example below:

snmp-server user NETOPS auth sha 5Er23@#as178 priv aes-128 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

snmp-server host 10.1.48.10 traps version 3 priv NETOPS

Encryption used by the SNMP users can be viewed via the show snmp user command as shown in the example below:

SW1# show snmp user
______________________________________________________________
 SNMP USERS 
______________________________________________________________

User Auth Priv(enforce) Groups acl_filter 
____ ____ ___________ ______ __________ 
NETOPS sha aes-128 network-operator 

If the Cisco switch is not configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm, this is a finding.

Fix Text

Configure the Cisco switch to encrypt SNMP messages using a FIPS 140-2 approved algorithm as shown in the example below:

SW1(config)# snmp-server user NETOPS auth sha xxxxxxxxxxxxx priv aes-128 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

SW1(config)# snmp-server host 10.1.48.10 traps version 3 priv NETOPS