SV-239864r891328_rule
V-239864
SRG-NET-000362-FW-000028
CASA-FW-000220
CAT I
10
Configure scanning threat detection as shown in the example below.
ASA(config)# threat-detection scanning-threat shun
NOTE: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled and this check is Not Applicable.
Review the ASA configuration to determine if scanning threat detection has been enabled.
threat-detection scanning-threat shun
NOTE: The parameter "shun" is an optional parameter in the Cisco documentation, but is required here to offer additional protection by dropping further connections from the threat.
If the ASA has not been configured to enable scanning threat detection, this is a finding.
V-239864
False
CASA-FW-000220
NOTE: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled and this check is Not Applicable.
Review the ASA configuration to determine if scanning threat detection has been enabled.
threat-detection scanning-threat shun
NOTE: The parameter "shun" is an optional parameter in the Cisco documentation, but is required here to offer additional protection by dropping further connections from the threat.
If the ASA has not been configured to enable scanning threat detection, this is a finding.
M
5339