IOS XE Switch STIG Checklist
20 items · Security · Medium difficulty · 4 hours
STIG-based hardening checklist for Cisco IOS XE switches.
-
Inventory all Cisco IOS XE switches in scope
List models, serials, locations, and management IPs.
-
Download the latest Cisco IOS XE Switch STIG
Retrieve the Y26M01 STIG and XCCDF package from cyber.mil.
-
Backup current device configurations and startup-configs
Save running and startup configs to secure storage before changes.
-
Verify current IOS version and installed image on each switch
Record software versions to compare against STIG requirements.
-
Schedule a maintenance window for upgrades and configuration changes
Notify users and coordinate outage times with stakeholders.
-
Apply IOS updates and security patches
Follow vendor upgrade procedures and validate images in lab when possible.
-
Configure secure management access
Harden device admin access and restrict how admins connect.
-
Enable SSH v2 and strong cryptographic algorithms
Disable legacy SSH versions and prefer strong ciphers and KEX.
-
Disable Telnet and HTTP server
Use SSH and HTTPS only for management; remove cleartext protocols.
-
Configure AAA with TACACS+ or RADIUS and role-based access
Centralize authentication and enforce least privilege for admins.
-
Configure NTP and ensure accurate time synchronization
Point to trusted NTP servers and secure NTP traffic where possible.
-
Configure secure logging and forward logs to a remote collector
Enable appropriate logging levels and send logs to a protected syslog.
-
Disable unnecessary services and legacy protocols
Turn off CDP, HTTP, SNMP v1/v2, and other unused features.
-
Implement port security and VLAN segmentation
Protect edge ports and separate management traffic into dedicated VLANs.
-
Set port-security limits and violation actions
Define maximum MAC addresses and configure violation behavior.
-
Disable unused ports and place them in a shutdown state
Administratively shut down or errdisable interfaces that are not in use.
-
Implement ACLs to restrict management access to trusted hosts
Limit SSH/HTTPS and management VLAN access to admin networks only.
-
Document configuration changes and update baselines
Record changes, update network diagrams, and save baseline configs.
-
Plan regular compliance audits and automated STIG scans
Schedule scans and remediation cycles to maintain STIG compliance.
-
Notify stakeholders and update change records after completion
Inform owners, close tickets, and report the maintenance outcome.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.