STIGQter STIGQter: STIG Summary: Cisco ASA Firewall Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to implement scanning threat detection.

DISA Rule

SV-239864r891328_rule

Vulnerability Number

V-239864

Group Title

SRG-NET-000362-FW-000028

Rule Version

CASA-FW-000220

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure scanning threat detection as shown in the example below.

ASA(config)# threat-detection scanning-threat shun

Check Contents

NOTE: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled and this check is Not Applicable.

Review the ASA configuration to determine if scanning threat detection has been enabled.

threat-detection scanning-threat shun

NOTE: The parameter "shun" is an optional parameter in the Cisco documentation, but is required here to offer additional protection by dropping further connections from the threat.

If the ASA has not been configured to enable scanning threat detection, this is a finding.

Vulnerability Number

V-239864

Documentable

False

Rule Version

CASA-FW-000220

Severity Override Guidance

NOTE: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled and this check is Not Applicable.

Review the ASA configuration to determine if scanning threat detection has been enabled.

threat-detection scanning-threat shun

NOTE: The parameter "shun" is an optional parameter in the Cisco documentation, but is required here to offer additional protection by dropping further connections from the threat.

If the ASA has not been configured to enable scanning threat detection, this is a finding.

Check Content Reference

M

Target Key

5339