Cisco NX-OS Switch STIG Hardening
22 items · Security · Hard difficulty · 4 hours
Quick STIG hardening checklist for Cisco NX-OS switches.
-
Verify device inventory and NX-OS version
Record model, serial, and NX-OS release to match applicable STIGs.
-
Verify image signatures and checksums
Check vendor-provided SHA256/RSA signatures before installing images.
-
Enable image verification and secure boot
Enable features that prevent unsigned images from booting.
-
Harden administrative access: configure AAA with TACACS+/RADIUS
Use centralized authentication and RBAC; avoid local-only auth.
-
Configure TACACS+ servers with secure keys
Add redundant servers and strong shared secrets; use TLS/TCP where supported.
-
Configure local user fallback and RBAC roles
Keep a locked-down local admin account for emergency access and map roles.
-
Configure local accounts: remove default accounts and set secure passwords
Delete or disable default accounts; use unique, strong passwords.
-
Enforce password policies: complexity, length, and aging
Apply minimum length, complexity rules, and periodic password rotation.
-
Enable SSH v2 and disable Telnet
Ensure only encrypted remote management is allowed.
-
Configure SSH keys and cipher policies
Prefer strong KEX and ciphers; rotate host keys periodically.
-
Limit management access: restrict management interfaces and source IPs
Restrict management to specific VLANs, interfaces, and trusted IPs.
-
Configure SNMPv3 with auth and encryption; disable SNMP v1/v2c
Use user-based SNMPv3 and AES/SHA; avoid community strings.
-
Configure SNMP views, groups, and ACLs
Limit OID access and restrict SNMP source IPs.
-
Configure logging: remote syslog, secure transport, and log retention
Send logs to a protected collector and set retention policies.
-
Configure NTP with authenticated sources and restrict access
Use authenticated NTP servers and allow NTP from trusted hosts.
-
Disable or restrict unnecessary services (HTTP, FTP, Telnet, BOOTP)
Turn off services not required to reduce the attack surface.
-
Apply ACLs for control-plane and management-plane protection
Use control-plane policing and management ACLs per STIG guidance.
-
Implement AAA accounting and logging for admin actions
Enable command accounting and log changes for audit trails.
-
Regularly apply patches and firmware updates per DISA guidance
Follow DISA STIG release notes and vendor advisories for updates.
-
Backup configurations and document baseline; store securely
Export configs and images, and save approved baselines off-box.
-
Test and validate configuration against STIG and produce report
Run XCCDF/SCAP scans, remediate findings, and retain evidence.
-
Subscribe to DISA Cyber Exchange for STIG updates and change notifications
Monitor cyber.mil for STIGs, errata, and maintenance schedules.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.