STIGQter STIGQter: STIG Summary: Cisco ASA Firewall Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must immediately use updates made to policy enforcement mechanisms such as firewall rules, security policies, and security zones.

DISA Rule

SV-239853r665845_rule

Vulnerability Number

V-239853

Group Title

SRG-NET-000019-FW-000004

Rule Version

CASA-FW-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove the command asp rule-engine transactional-commit access-group

ASA(config)# no asp rule-engine transactional-commit access-group

Check Contents

By default, when you change a rule-based policy such as access rules, the changes become effective immediately. With transactional model configured, the rules are not active until after compilation.

Review the ASA configuration and verify that the following command is not configured.

asp rule-engine transactional-commit access-group

If transactional-commit access-group has been configured, this is a finding.

Vulnerability Number

V-239853

Documentable

False

Rule Version

CASA-FW-000020

Severity Override Guidance

By default, when you change a rule-based policy such as access rules, the changes become effective immediately. With transactional model configured, the rules are not active until after compilation.

Review the ASA configuration and verify that the following command is not configured.

asp rule-engine transactional-commit access-group

If transactional-commit access-group has been configured, this is a finding.

Check Content Reference

M

Target Key

5339