1. Home
  2. Security Hardening
  3. DISA STIG Arista MLS DCS 7000 Series NDM V1R3
  4. AMLS-NM-000220 – The Arista Multilayer Switch must use multifactor authentication for local access to privileged accounts.

AMLS-NM-000220 – The Arista Multilayer Switch must use multifactor authentication for local access to privileged accounts.

Details

Multifactor authentication is defined as: using two or more factors to achieve authentication.

Factors include:

(i) Something a user knows (e.g., password/PIN);

(ii) Something a user has (e.g., cryptographic identification device, token); or

(iii) Something a user is (e.g., biometric).

To assure accountability and prevent unauthenticated access, privileged users must utilize multifactor authentication to prevent potential misuse and compromise of the system.

Local access is defined as access to an organizational information system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network.

Applications integrating with the DoD Active Directory and utilizing the DoD CAC are examples of compliant multifactor authentication solutions.

Solution

Configure the network device or its associated authentication server to use multifactor authentication for local access to privileged accounts.

To configure the local device to authenticate via its authentication server, enter the following command from the configuration mode interface. Replace the bracketed value with the configured server group name or the name of the server type to validate against all configured servers of that type.

switch(config)#aaa authentication login console group [radius] local

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Arista.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles