Rule version BCAS-ND-001690 · STIG v1 · 2026-09-16
Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. Bidirectional authentication provides stronger safeguards to validate the identity of other devices for connections that are of greater risk.
A local connection is any connection with a device communicating without the use of a network. A network connection is any connection with a device that communicates through a network (e.g., local area or wide area network, internet). A remote connection is any connection with a device communicating through an external network (e.g., the internet).
Because of the challenges of applying this requirement on a large scale, organizations are encouraged to only apply the requirement to those limited number (and type) of devices that truly need to support this capability.
Verify the SNMP agent version is set to "v3" and a USM local user is configured with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config snmp". 4. Review the output to ensure the agent version is "v3" and a "usm local user" is defined with appropriate authentication and privacy settings.
If the agent version is not "v3" or if a "usm local user" is not configured, this is a finding.
Configure the SNMP agent to version v3 and define a USM local user with HMAC authentication with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable", enter the password, enter "configure terminal", and then enter "snmp". 3. Enable the SNMPv3 agent by entering the following commands: "agent enabled" "agent version v3" 4. Create the USM user and enforce SHA (HMAC) authentication and AES privacy by typing (replacing bracketed text with site values): "usm local user [USERNAME]" "auth sha password [AUTH_PASSWORD]" "priv aes password [PRIV_PASSWORD]" "exit" 5. Map the user to a VACM group and enforce authenticated access by entering: "vacm group [GROUPNAME] member [USERNAME]" (Enter "usm" when prompted for sec-model) "exit" "vacm group [GROUPNAME] access usm auth-priv read-view cas-view write-view cas-view" 6. Enter "exit" and then "exit" again to leave configuration mode.