Rule version AWTM-NM-000001 · STIG v1 · 2026-09-14
Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. Bidirectional authentication provides stronger safeguards to validate the identity of other devices for connections that are of greater risk.
A local connection is any connection with a device communicating without the use of a network. A network connection is any connection with a device that communicates through a network (e.g., local area or wide area network, internet). A remote connection is any connection with a device communicating through an external network (e.g., the internet).
Because of the challenges of applying this requirement on a large scale, organizations are encouraged to only apply the requirement to those limited number (and type) of devices that truly need to support this capability.
1. Log in to the SSH CLI. 2. Enter "show running-config | include snmp". 3. Verify it shows as v3-only. 4. Verify the Auth Protocol displays as "sha256".
If SNMPv3 is not set to V3 with the authentication protocol of "sha256", this is a finding.
1. Log in to the SSH CLI. 2. Enter "configure terminal". 3. Enter "snmp v3-only". 4. Enter "user <user> role security" - replace <user> with the SNMPv3 username. 5. Enter the password for the user - it will not be able to be used to log in unless that role is allowed. 6. Enter "user <user> snmpv3 enabled min-sec-level authPriv auth-protocol hmac-sha-256 priv-protocol aes" - replace <user> with the SNMPv3 username. 7. Enter "user <user> snmpv3 auth-password <pass>" - replace <user> with the SNMPv3 username and <pass> with the authentication password. 8. Enter "user <user> snmpv3 priv-password <pass>" - replace <user> with the SNMPv3 username and <pass> with the privacy password. 9. Enter "snmp community <user>" - replace <user> with the SNMPv3 username. 10. Enter "Commit".