STIGQter STIGQter: STIG Summary: Cisco ASA Firewall Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to filter outbound traffic, allowing only authorized ports and services.

DISA Rule

SV-239852r665842_rule

Vulnerability Number

V-239852

Group Title

SRG-NET-000019-FW-000003

Rule Version

CASA-FW-000010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Step 1: Configure the ingress ACL similar to the example below.

ASA(config)# access-list INSIDE_INextended permit tcp any any eq https
ASA(config)# access-list INSIDE_INextended permit tcp any any eq http
ASA(config)# access-list INSIDE_INextended permit tcp any any eq …
ASA(config)# access-list INSIDE_INextended deny ip any any log

Step 2: Apply the ACL inbound on all internal interfaces as shown in the example below.

ASA(config)# access-group INSIDE_IN in interface INSIDE
ASA(config)# end

Check Contents

Review the ASA configuration to determine if it only permits outbound traffic using authorized ports and services.

Step 1: Verify that an ingress ACL has been applied to all internal interfaces as shown in the example below.

interface GigabitEthernet0/0
nameif INSIDE
security-level 100
ip address 10.1.11.1 255.255.255.0



access-group INSIDE _IN in interface INSIDE

Step 2: Verify that the ingress ACL only allows outbound traffic using authorized ports and services as shown in the example below.

access-list INSIDE _IN extended permit tcp any any eq www
access-list INSIDE _IN extended permit tcp any any eq https
access-list INSIDE _IN extended permit tcp any any eq …
access-list INSIDE _IN extended deny ip any any log

If the ASA is not configured to only allow outbound traffic using authorized ports and services, this is a finding.

Vulnerability Number

V-239852

Documentable

False

Rule Version

CASA-FW-000010

Severity Override Guidance

Review the ASA configuration to determine if it only permits outbound traffic using authorized ports and services.

Step 1: Verify that an ingress ACL has been applied to all internal interfaces as shown in the example below.

interface GigabitEthernet0/0
nameif INSIDE
security-level 100
ip address 10.1.11.1 255.255.255.0



access-group INSIDE _IN in interface INSIDE

Step 2: Verify that the ingress ACL only allows outbound traffic using authorized ports and services as shown in the example below.

access-list INSIDE _IN extended permit tcp any any eq www
access-list INSIDE _IN extended permit tcp any any eq https
access-list INSIDE _IN extended permit tcp any any eq …
access-list INSIDE _IN extended deny ip any any log

If the ASA is not configured to only allow outbound traffic using authorized ports and services, this is a finding.

Check Content Reference

M

Target Key

5339