Enable Password Complexity Requirements for Local Credentials Details While configuring a back-end authentication store is the recommended configuration, at least one local administrative account must be configured....
Ensure Idle Timeout for Login Sessions is set to 5 minutes – console exec-timeout Details Verify device is configured to automatically disconnect sessions after a fixed idle time. Rationale: This prevents unauthorized users from...
Ensure Idle Timeout for Login Sessions is set to 5 minutes – ssh idle-timeout Details Verify device is configured to automatically disconnect sessions after a fixed idle time. Rationale: This prevents unauthorized users from...
Ensure Syslog Logging is configured – logging level Details Logging should be configured such that: Logging level is set to a level sufficient for the target device Logs...
Ensure Syslog Logging is configured – logging server/source-interface Details Logging should be configured such that: Logging level is set to a level sufficient for the target device Logs...
If a Local Time Zone is used, Configure Daylight Savings Details If local time zones are configured on network infrastructure, it is important to also configure the time ‘shift’ that...
If Possible, Limit the BGP Routes Accepted from Peers Details Once a BGP relationship is established, the BGP process will accept routes from any connected peers and consider those...
If VLAN interfaces have IP addreses, configure anti spoofing / ingress filtering protections Details If VLAN interfaces have IP addresses, it is important that anti-spoofing protections are in place, to prevent an attacker...
Log all Successful and Failed Administrative Logins Details By default failed logins are logged, but successful logins are not logged. This makes any configuration changes or successful...
Log OSPF Adjacency Changes Details Logging changes to the BGP peering relationships is recommended. Rationale: Any logged changes in a routing peer relationship will...