[ Applies to ] StorageGuard / NetApp ONTAP / Unified Storage
This article lists the recommended baseline checks for NetApp ONTAP. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
NetApp ONTAP is the storage operating system for NetApp AFF and FAS systems, ONTAP Select and Cloud Volumes ONTAP, providing unified block, file and object services.
Why hardening NetApp ONTAP matters
ONTAP clusters store large amounts of business-critical data. Hardening cluster and SVM access, authentication, encryption, protocols, auditing, Autonomous Ransomware Protection and SnapLock keeps that data secure and recoverable.
Recommended baseline checks
The baseline below contains 252 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-C0393T187V01 | Account lockout threshold |
| SG-C0384T187V01 | Active Telnet (Firewall policy) |
| SG-C0307T187V01 | Admin account status |
| SG-M7755T187V01 | Admin group mapping |
| SG-M5843T187V01 | Admin password complexity |
| SG-M6620T187V01 | AES encryption for CIFS |
| SG-M4201T187V01 | Aggr mirror status |
| SG-M1133T187V01 | Allowed protocols |
| SG-C0126T187V01 | Anonymous user access |
| SG-M2932T187V01 | Anonymous user mapping |
| SG-M7268T187V01 | Anti-ransomware configuration |
| SG-F7745T187V01 | Anti-ransomware status |
| SG-M3135T187V01 | Antivirus server redundancy |
| SG-C0163T187V01 | Approved AD domain |
| SG-C0332T187V01 | Approved admin roles |
| SG-M9546T187V01 | Approved admin user / group |
| SG-C0449T187V01 | Approved DNS servers |
| SG-C0435T187V01 | Approved LDAP servers |
| SG-C0013T187V01 | Approved NTP servers |
| SG-C0348T187V01 | Approved SNMP trap hosts |
| SG-C0015T187V01 | Approved Syslog servers |
| SG-C0733T187V01 | ARP attack probability detected |
| SG-C0732T187V01 | ARP volume protection state |
| SG-F8659T187V01 | Audit log retention |
| SG-C0001T187V01 | Audit logging status |
| SG-C0031T187V01 | Authentication server configuration |
| SG-C0024T187V01 | Authentication server redundancy |
| SG-C0552T187V01 | Authorization policy rules |
| SG-C0165T187V01 | Authorization policy status |
| SG-M8335T187V01 | Autosupport digital certificate validation |
| SG-C0430T187V01 | Autosupport status |
| SG-C0033T187V01 | Central authentication for CIFS SMB file share access |
| SG-M3590T187V01 | Central authentication for file share access |
| SG-M9528T187V01 | Central Certificate Authority (CA) status |
| SG-C0030T187V01 | Centralized authentication service status - CIFS |
| SG-C0030T187V02 | Centralized authentication service status - Cluster |
| SG-C0029T187V01 | Centralized log server |
| SG-C0233T187V01 | Centralized log server redundancy |
| SG-M4202T187V01 | Certificate algorithm |
| SG-M6094T187V01 | Certificate Issuer |
| SG-M6688T187V01 | CIFS AD session security level |
| SG-M2409T187V01 | CIFS dialect for widelinks access |
| SG-M3582T187V01 | CIFS domain password change |
| SG-M2554T187V01 | CIFS encryption for DC connections |
| SG-M5214T187V01 | CIFS file access to non-owners |
| SG-M8995T187V01 | CIFS password complexity |
| SG-C0545T187V01 | CIFS Password complexity required |
| SG-M1473T187V01 | CIFS server minimum authentication security level |
| SG-C0128T187V01 | CIFS SMB anonymous user access restriction |
| SG-C0343T187V01 | CIFS SMB encryption (policy) |
| SG-C0344T187V01 | CIFS SMB server signing |
| SG-C0122T187V01 | CIFS SMB version enabled |
| SG-M4046T187V01 | CIFS SMBv1 status |
| SG-M3828T187V01 | Cluster peer min passphrase length |
| SG-F2532T187V01 | Concurrent session limit |
| SG-M4347T187V01 | Configuration backup |
| SG-C0065T187V02 | Data at-rest encryption (disk) |
| SG-C0065T187V01 | Data at-rest encryption (logical) |
| SG-M8400T187V01 | Data encryption status |
| SG-C0080T187V01 | Data in-transit encryption - IPsec |
| SG-C0080T187V02 | Data in-transit encryption - NFS Export |
| SG-C0097T187V01 | Data retention mode |
| SG-C0098T187V01 | Data retention period |
| SG-M2602T187V01 | DDNS status |
| SG-C0056T187V01 | Default passwords |
| SG-C0308T187V01 | Diag account status |
| SG-C0243T187V01 | DNS server configuration |
| SG-C0060T187V01 | DNS server redundancy |
| SG-M3552T187V01 | DNS service status |
| SG-C0551T187V01 | Dynamic authorization status |
| SG-M6484T187V01 | Email notification |
| SG-C0737T187V01 | EMS ransomware alert destination |
| SG-F7889T187V01 | Encryption required for DC connections (CIFS) |
| SG-C0602T187V01 | End of extended support |
| SG-C0600T187V01 | End of support |
| SG-C0162T187V04 | Expired SSL certificate - OU |
| SG-M6246T187V01 | External file policy server |
| SG-F3936T187V01 | External file policy server communication encryption |
| SG-M6157T187V01 | External fpolicy server resilient logging |
| SG-M9343T187V01 | External policy engine SSL option |
| SG-F2175T187V01 | File ownership change permission - NFS default |
| SG-C0325T187V01 | File share access rights |
| SG-M8025T187V01 | File share client access list |
| SG-C0177T187V01 | FIPS mode status |
| SG-M5470T187V01 | Firewall logging status |
| SG-M7286T187V01 | Firewall restrictions |
| SG-C0195T187V01 | Firewall status |
| SG-C0806T187V01 | FPolicy abort timeout |
| SG-C0808T187V01 | FPolicy connection |
| SG-C0810T187V01 | FPolicy NFS event noise-reduction filters |
| SG-C0809T187V01 | FPolicy send-buffer minimum |
| SG-C0807T187V01 | FPolicy server redundancy |
| SG-C0805T187V01 | FPolicy SSL |
| SG-M7827T187V01 | FTP service status |
| SG-C0602T187V02 | Future end of extended support |
| SG-C0600T187V02 | Future end of support |
| SG-C0381T187V01 | HTTP service status |
| SG-M3152T187V01 | HTTP service status (node) |
| SG-C0209T187V01 | Idle session timeout - CLI |
| SG-C0261T187V01 | Initial password change |
| SG-M1604T187V01 | Ipsec configuration |
| SG-C0141T187V01 | IPv6 status |
| SG-M3376T187V01 | iSCSI initiator authentication |
| SG-M1613T187V01 | iSCSI interface ACL |
| SG-M7013T187V01 | ISNS configuration |
| SG-M4193T187V01 | Kerberos configuration |
| SG-F2678T187V01 | KEX algorithm strength |
| SG-F6222T187V01 | Key server configuration |
| SG-M1585T187V01 | Key size |
| SG-M5268T187V01 | KMIP configuration |
| SG-C0052T187V01 | KMS server redundancy |
| SG-M1263T187V01 | LDAP client session security |
| SG-C0039T187V01 | LDAP server configuration |
| SG-C0025T187V01 | LDAP server redundancy |
| SG-C0427T187V01 | Login banner message |
| SG-C0426T187V01 | Login banner status |
| SG-C0234T187V01 | Maximum password age |
| SG-C0234T187V02 | Maximum password age - CIFS machine account |
| SG-C0392T187V01 | Minimum account lockout duration |
| SG-C0262T187V01 | Minimum password age |
| SG-C0270T187V01 | Minimum password digits |
| SG-C0264T187V01 | Minimum password length |
| SG-C0271T187V01 | Minimum password lowercase characters |
| SG-C0272T187V01 | Minimum password special characters |
| SG-C0273T187V01 | Minimum password uppercase characters |
| SG-M6081T187V01 | Multi-admin-verify group |
| SG-M7598T187V01 | Multi-admin-verify rules |
| SG-M4757T187V01 | Multi-admin-verify status |
| SG-C0239T187V01 | Multi-factor authentication |
| SG-C0242T187V01 | NDMP authentication type |
| SG-M5867T187V01 | NDMP cleartext password |
| SG-M8362T187V01 | NDMP node-scoped mode |
| SG-M8024T187V01 | NDMP password length |
| SG-C0247T187V01 | Neighbor discovery protocol status |
| SG-M8665T187V01 | NetBIOS over TCP status |
| SG-M6016T187V01 | NetBIOS status |
| SG-F1698T187V01 | NFS ACL enabled |
| SG-M4995T187V01 | NFS AUTH_SYS extended groups status |
| SG-M2258T187V01 | NFS cached credential time |
| SG-M6651T187V01 | NFS checksum for replay-cache |
| SG-M5167T187V01 | NFS encryption strength |
| SG-C0191T187V01 | NFS export ACL status |
| SG-M8809T187V01 | NFS export rule setuid status |
| SG-M6172T187V01 | NFS File ownership change permission |
| SG-C0544T187V01 | NFS Idle Connection Timeout |
| SG-M6446T187V01 | NFS over UDP |
| SG-M1431T187V01 | NFS privileged ports |
| SG-M1623T187V01 | NFS unknown UID mapping |
| SG-C0121T187V01 | NFS versions enabled |
| SG-F3955T187V01 | NFS weak Kerberos encryption types |
| SG-M2074T187V01 | NFSv3 MS-DOS client support |
| SG-M9897T187V01 | NFSv3 security changes |
| SG-C0361T187V01 | Node autosupport unencrypted data transport |
| SG-M3351T187V01 | Node Autosupport unsecure transport |
| SG-F8684T187V01 | Node SSH IP ACL (IPv6) |
| SG-C0231T187V01 | Non-default local users |
| SG-M2264T187V01 | Nosuid option enabled |
| SG-C0171T187V01 | NTP server configuration |
| SG-C0432T187V01 | NTP server redundancy |
| SG-M5529T187V01 | Number of disallowed past passwords |
| SG-M5056T187V01 | Object store security settings |
| SG-M9592T187V01 | OCSP configuration |
| SG-F7601T187V01 | ONTAP SP REST API restriction |
| SG-C0417T187V01 | Password hash strength |
| SG-C0284T187V03 | Password history |
| SG-M1029T187V01 | Password rules status |
| SG-F8711T187V01 | Peer cluster authentication status |
| SG-F9021T187V01 | Peer cluster secure configuration |
| SG-F7184T187V01 | Peer to peer comm security: auth-status |
| SG-F3568T187V01 | Peer to peer comm security: encryption-protocol |
| SG-M9316T187V01 | Peer to peer communication authentication |
| SG-M9046T187V01 | Peer to peer communication encryption |
| SG-M4264T187V01 | Permitted encryption types for NFS Kerberos |
| SG-C0456T187V01 | Ransomware protection policy |
| SG-M3867T187V01 | Ransomware protection policy definition |
| SG-M9682T187V01 | Remote copy |
| SG-M7943T187V01 | Remote support status |
| SG-F1067T187V01 | Replication link encryption |
| SG-C0450T187V01 | Required DNS servers |
| SG-M5243T187V01 | Required External (central) log servers |
| SG-C0439T187V01 | Required LDAP servers |
| SG-C0014T187V01 | Required NTP servers |
| SG-C0349T187V01 | Required SNMP trap hosts |
| SG-C0016T187V01 | Required Syslog servers |
| SG-M3911T187V01 | Root (vol0) volume export |
| SG-M1456T187V01 | Root user status |
| SG-C0383T187V01 | RSH service status |
| SG-F2870T187V01 | Secure data copy retention |
| SG-M5846T187V01 | Secure data copy retention (snaplock config) |
| SG-M3331T187V01 | Secure LDAP for CIFS connections |
| SG-M9439T187V01 | Secure NDMP (NDMP SSL) used |
| SG-C0008T187V01 | Secure NTP status |
| SG-C0004T187V01 | Security audit logging - read-only |
| SG-C0167T187V01 | Security officer account |
| SG-M9450T187V01 | Security types for NFS export |
| SG-C0447T187V02 | Self-signed certificate - OU |
| SG-C0114T187V01 | Sensitive data removal - autosupport |
| SG-M9714T187V01 | Session timeout |
| SG-C0459T187V01 | Share scan status |
| SG-M6098T187V01 | Signing for CIFS traffic |
| SG-M1039T187V01 | SMB encryption enabled |
| SG-M4743T187V01 | SMB version enabled for DC connections |
| SG-M5724T187V01 | SMTP configuration |
| SG-C0734T187V01 | SnapLock Compliance mode enforced |
| SG-M8834T187V01 | Snaplock retention |
| SG-M2362T187V01 | Snaplock type |
| SG-C0735T187V01 | SnapMirror replication encryption |
| SG-M7833T187V01 | Snapshot autodelete configuration |
| SG-C0300T187V01 | Snapshot autodeletion |
| SG-C0058T187V01 | SNMP community default string |
| SG-M9022T187V01 | SNMP community permission |
| SG-M2558T187V01 | SNMP min severity |
| SG-C0155T187V01 | SNMP service disabled |
| SG-C0347T187V01 | SNMP trap host configuration |
| SG-F3148T187V01 | SNMP Trap status |
| SG-C0123T187V01 | SNMP versions enabled |
| SG-M4357T187V01 | SP firmware image |
| SG-M2552T187V01 | SP IPv6 |
| SG-M3341T187V01 | SP SSH ACL |
| SG-C0715T187V01 | SP SSH Allowed Addresses (IPv4) - IPv4 |
| SG-C0716T187V01 | SP SSH Allowed Addresses (IPv6) - IPv6 |
| SG-C0258T187V01 | SSH cipher strength |
| SG-C0255T187V01 | SSH MAC strength |
| SG-C0124T187V01 | SSHv1 status |
| SG-C0365T187V01 | SSL authentication status |
| SG-M2643T187V01 | SSL certificate status |
| SG-M8210T187V01 | SSL options |
| SG-M6362T187V01 | Storage protocol status |
| SG-F1838T187V01 | Storage protocol status |
| SG-C0306T187V01 | Syslog communication protocol |
| SG-M4937T187V01 | Syslog min severity |
| SG-M9723T187V01 | Syslog server authentication |
| SG-C0019T187V01 | Target OS version |
| SG-C0385T187V01 | Telnet service status |
| SG-M9101T187V01 | Time server (NTP) authentication |
| SG-C0390T187V01 | TLS level |
| SG-C0448T187V02 | Trusted certificate-authority (CA) - OU |
| SG-C0116T187V01 | Unapproved admin users |
| SG-F4168T187V01 | Unapproved user groups |
| SG-C0017T187V01 | Unauthenticated Syslog server |
| SG-M7979T187V01 | Unencrypted syslog traffic |
| SG-C0429T187V01 | Unused FC ports |
| SG-C0140T187V01 | Unused ports |
| SG-M2756T187V01 | Unused protocols |
| SG-M6496T187V01 | Updated node security settings |
| SG-C0213T187V01 | Use of secure LDAP - CIFS |
| SG-C0213T187V02 | Use of secure LDAP - Cluster |
| SG-C0213T187V03 | Use of secure LDAP - Name Services |
| SG-C0148T187V01 | User protocols status |
| SG-F5450T187V01 | User role configuration |
| SG-M4798T187V01 | Vscan-on-access-policy status |
| SG-M5331T187V01 | Vserver vscan status |
Related components
A complete baseline also covers the components that manage, connect to or protect NetApp ONTAP. Review the configuration of:
- Active IQ Unified Manager
- ONTAP tools for VMware vSphere
- NetApp cluster switches
- SnapCenter and SnapMirror peers
- Amazon FSx for NetApp ONTAP
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.