STIGQter STIGQter: STIG Summary: Cisco ASA Firewall Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to inspect all inbound and outbound traffic at the application layer.

DISA Rule

SV-239869r665893_rule

Vulnerability Number

V-239869

Group Title

SRG-NET-000364-FW-000040

Rule Version

CASA-FW-000270

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the firewall to inspect all inbound and outbound traffic at the application layer.

ASA(config)# service-policy global_policy global
ASA(config)# end

Check Contents

Review the firewall configuration to verify that inspection for applications deployed within the network is being performed on all interfaces. The following command should be configured: service-policy global_policy global

If the firewall is not configured to inspect all inbound and outbound traffic at the application layer, this is a finding.

Vulnerability Number

V-239869

Documentable

False

Rule Version

CASA-FW-000270

Severity Override Guidance

Review the firewall configuration to verify that inspection for applications deployed within the network is being performed on all interfaces. The following command should be configured: service-policy global_policy global

If the firewall is not configured to inspect all inbound and outbound traffic at the application layer, this is a finding.

Check Content Reference

M

Target Key

5339