Network Device Management Rules : Generating SNMP alerts when local accounts are created
  
Generating SNMP alerts when local accounts are created
Rule Title: RiOS must generate alerts that can be forwarded to the administrators and ISSO when local accounts are created.
STIG ID: RICX-DM-000011
Rule ID: SV-77337r1_rule Severity: CAT II
Vuln ID: V-62847 Class: Unclass
An authorized insider or individual who maliciously creates a local account could gain immediate access from a remote location to privileged information on a critical security device. Sending an alert to the administrators and ISSO when this action occurs greatly reduces the risk that accounts will be secretly created.
RiOS can be configured to send an SNMP trap to the SNMP server. It also sends a message to the syslog and the local log. Either of these methods results in an alert that can be forwarded to authorized accounts.
Verifying that administrators have the correct security privileges
Verify that RiOS captures an SNMP trap for user creation events that can be sent to the ISSO and designated administrators by the SNMP server.
To verify that administrators have the correct privilege level
1. Connect to the Management Console.
2. Choose Administration > Security: User Permissions to display the User Permissions page.
3. Verify that the privilege level is correct for each administrator. If the privilege level settings are not in accordance with applicable policy, this is a security vulnerability finding.
Configuring the correct security privileges for administrators
Configure RiOS to capture an SNMP trap for user creation events that can be sent to the information system security officer (ISSO) and designated administrators by the SNMP server.
To configure security privileges for administrators
1. Connect to the Management Console.
2. Choose Administration > Security: User Permissions to display the User Permissions page.
3. Click Add a New Account to expand the page.
4. Set the values of Roles and Permissions according to the privilege level in accordance with applicable policy.
Control
Description
Account Name
Specify a name for the role-based account.
Password
Specify a password in the text box, and then retype the password for confirmation.
Enable Account
Select the check box to enable the new account.
Administrator
Configures a system administrator role. This role allows permission for all other RBM roles, including creating, editing, and removing user accounts. The system administrator role allows you to add or remove a system administrator role for any other user, but not for yourself. Read-only permission is not allowed for this role.
User
Configures a role that determines whether the user:
has permission to view current configuration settings but not change them (Read-Only).
has permission to view settings and make configuration changes for a feature (Read/Write).
cannot view or save settings or configuration changes for a feature (Deny).
General Settings
Configures per-source IP connection limit and the maximum connection pooling size.
Network Settings
Configures host and network interface settings, including DNS cache settings and hardware assist rules.
QoS
Enforces QoS policies.
Path Selection
Configures path selection.
Optimization Service
Configures alarms, performance features, SkipWare, HS-TCP, and TCP optimization.
In-Path Rules
Configures TCP traffic for optimization and how to optimize traffic by setting in-path rules. This role includes WAN visibility to preserve TCP/IP address or port information.
For details about WAN visibility, see the SteelHead Deployment Guide.
CIFS Optimization
Configures CIFS optimization settings (including SMB-signing) and Overlapping Open optimization.
HTTP Optimization
Configures enhanced HTTP optimization settings: URL learning, Parse and Prefetch, Object Prefetch Table, keep-alive, insert cookie, file extensions to prefetch, and the ability to set up HTTP optimization for a specific server subnet.
Oracle Forms Optimization
Optimizes Oracle E-business application content and forms applications.
MAPI Optimization
Optimizes MAPI and sets Exchange and NSPI ports.
NFS Optimization
Configures NFS optimization.
Notes Optimization
Configures Lotus Notes optimization.
Citrix Optimization
Configures Citrix optimization.
SSL Optimization
Configures SSL support and the secure inner channel.
Replication Optimization
Configures the SRDF/A, FCIP, and SnapMirror storage optimization modules.
Proxy File Service (PFS)
Configures the PFS.
Riverbed Services Platform (RSP)
Configures functionality into a virtualized environment on the client SteelHead appliance. The functionality can include third-party packages such as a firewall security package, a streaming video server, or a package that provides core networking services (for example, DNS and DHCP). This role includes permission to install VMware tools and add subnet side rules. For details, see the RSP User’s Guide.
Granite Branch (SteelFusion Edge) Storage Service
Configures branch storage services on SteelFusion Edge appliances (the branch storage services are only available on a SteelHead EX appliance).
Security Settings
Configures security settings, including RADIUS and TACACS authentication settings and the secure vault password.
Basic Diagnostics
Customizes system diagnostic logs, including system and user log settings, but does not include TCP dumps.
TCP Dumps
Customizes TCP dump settings and allows use of the Shark function for detailed packet analysis through Cascade Pilot.
Reports
Sets system report parameters.
Domain Authentication
Allows joining a Windows domain and configuring Windows domain authentication.
Citrix Acceleration
Configures Citrix optimization.
Add
Adds your settings to the system.
Remove Selected Accounts
Select the check box next to the name and click Remove Selected.
5. Click Apply.