Check: NET0422
Network - Firewall:
NET0422
(in versions v8 r25 through v8 r21)
Title
Network devices must be configured with rotating keys used for authenticating IGP peers that have a duration of 180 days or less. (Cat III impact)
Discussion
If the keys used for routing protocol authentication are guessed, the malicious user could create havoc within the network by advertising incorrect routes and redirecting traffic. Changing the keys frequently reduces the risk of them eventually being guessed. When configuring authentication for routing protocols that provide key chains, configure two rotating keys with overlapping expiration dates, both with 180-day or less expirations.
Check Content
Review device configuration for key expirations of 180 days or less. If rotating keys are not configured to expire at 180 days or less, this is a finding.
Fix Text
Configure the device so rotating keys expire at 180 days or less.
Additional Identifiers
Rule ID:
Vulnerability ID: V-14667
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |