STIGQter STIGQter: STIG Summary: Cisco ASA Firewall Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to enable threat detection to mitigate risks of denial-of-service (DoS) attacks.

DISA Rule

SV-239860r991796_rule

Vulnerability Number

V-239860

Group Title

SRG-NET-000193-FW-000030

Rule Version

CASA-FW-000150

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure threat detection as shown in the example below.

ASA(config)# threat-detection basic-threat

Check Contents

NOTE: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled, and this check is Not Applicable.

Review the ASA configuration to determine if threat detection has been enabled.

threat-detection basic-threat

If the ASA has not been configured to enable threat detection to mitigate risks of DoS attacks, this is a finding.

Vulnerability Number

V-239860

Documentable

False

Rule Version

CASA-FW-000150

Severity Override Guidance

NOTE: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled, and this check is Not Applicable.

Review the ASA configuration to determine if threat detection has been enabled.

threat-detection basic-threat

If the ASA has not been configured to enable threat detection to mitigate risks of DoS attacks, this is a finding.

Check Content Reference

M

Target Key

5339