[ Applies to ] StorageGuard / NetApp StorageGRID / Object Storage
This article lists the recommended baseline checks for NetApp StorageGRID. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
NetApp StorageGRID is a software-defined, geographically distributed object storage system that stores and manages large volumes of data across multiple sites with policy-driven lifecycle management.
Why hardening NetApp StorageGRID matters
StorageGRID often holds confidential documents, customer data and intellectual property, making it an attractive target. Endpoint, firewall, encryption and authentication settings protect stored objects and support compliance with frameworks such as PCI DSS and HIPAA.
Recommended baseline checks
The baseline below contains 138 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-M6265T193V01 | Accept inbound client traffic only on explicitly configured endpoints |
| SG-C0399T193V01 | Active system alert detected |
| SG-M6513T193V01 | Admin proxy for AutoSupport |
| SG-M8511T193V01 | Alarms configuration |
| SG-M8654T193V01 | Alerts configuration |
| SG-M4460T193V01 | All internal traffic ports on the Admin Network are blocked |
| SG-M7391T193V01 | Anonymous access is disabled for S3 accounts |
| SG-C0449T193V01 | Approved DNS servers |
| SG-M2104T193V01 | Approved ILM policy configuration |
| SG-C0095T193V01 | Approved information lifecycle management policy configuration |
| SG-M8243T193V01 | Approved IPMI version |
| SG-C0044T193V01 | Approved KMS server |
| SG-C0013T193V01 | Approved NTP servers |
| SG-M8801T193V01 | Approved StorageGRID software version |
| SG-C0015T193V01 | Approved Syslog servers |
| SG-M8191T193V01 | Audit level |
| SG-M8974T193V01 | AutoSupport state |
| SG-M5341T193V01 | AutoSupport transport protocol |
| SG-M2067T193V01 | BMC management port status |
| SG-C0023T193V01 | Bucket versioning status |
| SG-C0029T193V01 | Centralized log server |
| SG-C0233T193V01 | Centralized log server redundancy |
| SG-M7006T193V01 | Certificate expiration time |
| SG-M4905T193V01 | Certificate issuer |
| SG-M1471T193V01 | CLB service on Gateway Nodes not used |
| SG-M8397T193V01 | Client Network on the Gateway Node is untrusted |
| SG-M8621T193V01 | Client Network on the Storage Node is untrusted |
| SG-M8881T193V01 | Cross-Origin Resource Sharing (CORS) |
| SG-C0065T193V01 | Data at-rest encryption |
| SG-M6360T193V01 | Data encryption algorithm strength |
| SG-C0081T193V01 | Data in-transit encryption algorithm |
| SG-M6421T193V01 | Deactivated system features |
| SG-M8187T193V01 | Default certificates replaced |
| SG-C0243T193V01 | DNS server configuration |
| SG-C0060T193V01 | DNS server redundancy |
| SG-M4925T193V01 | Drive Security keys configured |
| SG-C0602T193V01 | End of extended support |
| SG-C0600T193V01 | End of support |
| SG-C0388T193V01 | Enforce TLSv1.2 |
| SG-C0175T193V01 | Event types enabled for audit logging |
| SG-C0162T193V01 | Expired SSL certificate - management |
| SG-C0162T193V02 | Expired SSL certificate - storage API |
| SG-M5789T193V01 | Federated user group status |
| SG-M4881T193V01 | FIPS compliance |
| SG-C0177T193V01 | FIPS mode status |
| SG-C0195T193V01 | Firewall status |
| SG-C0602T193V02 | Future end of extended support |
| SG-C0600T193V02 | Future end of support |
| SG-M2878T193V01 | Hardware variance |
| SG-M1330T193V01 | Hashing function for S3 access keys |
| SG-M4289T193V01 | HTTP protocol status |
| SG-C0381T193V01 | HTTP service status |
| SG-C0209T193V01 | Idle session timeout |
| SG-M6594T193V01 | ILM rule configuration |
| SG-C0100T193V01 | Information lifecycle management rule configuration |
| SG-M1364T193V01 | IPMI anonymous user access |
| SG-M8731T193V01 | IPMI default password |
| SG-M5135T193V01 | IPMI IP ACL |
| SG-M2827T193V01 | IPMI security |
| SG-M1736T193V01 | IPMI Serial over LAN |
| SG-M9422T193V01 | IPMI status |
| SG-M1935T193V01 | IPMI user list |
| SG-M7012T193V01 | Key exchange algorithms for SSH connections |
| SG-C0049T193V01 | KMS server configuration |
| SG-C0052T193V01 | KMS server redundancy |
| SG-M6701T193V01 | KMS server status |
| SG-M5898T193V01 | Local Azure secure LDAP |
| SG-C0041T193V01 | Local identity provider status |
| SG-M6001T193V01 | Local secure LDAP |
| SG-M4668T193V01 | MAC algorithm for SSH connections |
| SG-M7226T193V01 | Management Interface Server Certificate |
| SG-M1608T193V01 | Minimum data protection level |
| SG-C0239T193V01 | Multi-factor authentication |
| SG-M6411T193V01 | No use of wildcard certificates (except S3 virtual hosted style endpoint) |
| SG-M8297T193V01 | Node encryption with KMS |
| SG-C0171T193V01 | NTP server configuration |
| SG-C0432T193V01 | NTP server redundancy |
| SG-M5659T193V01 | Object Storage API Service Endpoints Server Certificate |
| SG-C0102T193V01 | Object-lock status |
| SG-C0446T193V01 | Required certificate authority (CA) servers - management |
| SG-C0446T193V02 | Required certificate authority (CA) servers - storage API |
| SG-C0450T193V01 | Required DNS servers |
| SG-C0051T193V01 | Required KMS server |
| SG-C0014T193V01 | Required NTP servers |
| SG-C0016T193V01 | Required Syslog servers |
| SG-M6803T193V01 | Restrict access to SANtricity System Manager |
| SG-M7802T193V01 | Restrict SSH access to trusted clients |
| SG-M4170T193V01 | Restricted access to admin node |
| SG-M2164T193V01 | Restricted access to storage node |
| SG-C0447T193V01 | Self-signed certificate - management |
| SG-C0447T193V02 | Self-signed certificate - storage API |
| SG-M8850T193V01 | Self-signed certificates not used |
| SG-M3627T193V01 | Separated Admin Nodes for grid administrators and tenant users |
| SG-M1737T193V01 | Separated client, administration, and internal grid networks |
| SG-M4052T193V01 | Separated Grid Manager and Tenant Manager communications |
| SG-M6624T193V01 | Shared port 443 blocked |
| SG-M3806T193V01 | Silenced critical alerts |
| SG-M2683T193V01 | SMTP server configuration |
| SG-M6782T193V01 | SNMP authentication |
| SG-M5710T193V01 | SNMP communication protocol (TCP) |
| SG-C0058T193V01 | SNMP community default string |
| SG-M1328T193V01 | SNMP privacy |
| SG-C0155T193V01 | SNMP service disabled |
| SG-C0156T193V01 | SNMP service enabled |
| SG-C0347T193V01 | SNMP trap host configuration |
| SG-C0123T193V01 | SNMP versions enabled |
| SG-C0351T193V01 | SNMPv3 read-only user |
| SG-C0346T193V02 | SNMPv3 user security |
| SG-M4464T193V01 | SNMPv3 user status |
| SG-M3317T193V01 | SSH authentication types |
| SG-M8003T193V01 | SSH ciphers |
| SG-M1947T193V01 | SSH version |
| SG-M7859T193V01 | Storage proxy for communication to external services |
| SG-C0306T193V01 | Syslog communication protocol |
| SG-M4201T193V01 | Syslog server |
| SG-M2163T193V01 | Target BMC firmware |
| SG-C0019T193V01 | Target OS version |
| SG-M7201T193V01 | Tenant Azure secure LDAP |
| SG-M5034T193V01 | Tenant identity provider |
| SG-C0072T193V01 | Tenant object encryption status |
| SG-M5291T193V01 | Tenant secure LDAP |
| SG-M5035T193V01 | TLS level |
| SG-C0448T193V01 | Trusted certificate-authority (CA) - management |
| SG-C0448T193V02 | Trusted certificate-authority (CA) - storage API |
| SG-M6480T193V01 | Untrusted tenant: identity source limited |
| SG-M2701T193V01 | Untrusted tenant: use of platform services disallowed |
| SG-M8843T193V01 | Untrusted tenants: no direct access to Tenant Management API |
| SG-M2733T193V01 | Untrusted tenants: no direct access to the Tenant Manager |
| SG-M4146T193V01 | Untrusted traffic on port 623 blocked |
| SG-M1956T193V01 | Unused CIFS |
| SG-M3551T193V01 | Unused NFS |
| SG-C0213T193V01 | Use of secure LDAP |
| SG-M9776T193V01 | Version for signing S3 API requests |
| SG-C0260T193V01 | Weak cipher suites |
| SG-M2656T193V01 | Weak object encryption algorithms |
| SG-C0075T193V01 | Weak object encryption and hash algorithms |
| SG-M8927T193V01 | Weak object hash algorithms |
| SG-M6160T193V01 | WORM protection |
Related components
A complete baseline also covers the components that manage, connect to or protect NetApp StorageGRID. Review the configuration of:
- Underlying node operating systems and hypervisors
- Cloud storage pools and platform services
- Load balancers
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.