See below for the detailed notes for 7.6.1. Need the latest build? Download Indeni.
The new “CIS Benchmark test failed” Auto Detect Element (ADE) in 7.6 has been split into multiple elements instead of one ADE containing all failed checks. This makes it possible to modify the threshold defined by the CIS Benchmark to fit the user’s local thresholds. The new ADEs are:
- Check for Strong passwords
- Ensure password complexity is set to 3
- SSH session timeout for inactivity
- Ensure “Login Banner” is set
- Ensure SSH v2 is used
- Ensure that the local admin user accounts will not be blocked by checking that the CLI accounts are not being blocked under any circumstances.
You will find more information in this “Infrastructure Automation with Indeni 7.6” blog post.
- IKP-4502 CHKP – Concurrent Connections Count wrong on Scalable Platform R80.20SP
- IKP-4511 PAN – cross_vendor_cluster_member_no_longer_active_vsx – does not trigger for multi-vsys (i.e. VSX): cluster member alerting per vsys fixed, one alert per each vsys defined into the cluster is triggered when a member of the cluster is no longer active