SV-239873r665932_rule
V-239873
SRG-NET-000074-IDPS-00059
CASA-IP-000040
CAT II
10
Enable logging for connection events.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.
Step 2: Click the edit icon next to the access control policy you want to configure. The access control policy editor appears.
Step 3: Click the edit icon next to a rule to edit. Select a logging option either log at Beginning and End of Connection or log at End of Connection. Select the Syslog check box.
Step 4: Click Save.
---------------------------------------------------
Enable logging for Intrusion events.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.
Step 2: Click Advanced Setting. The Advanced Settings page appears.
Step 3: If Syslog Alerting under External Responses is enabled, click Edit. If the configuration is disabled, click Enabled, then click Edit. The Syslog Alerting page appears.
Step 4: In the Logging Hosts field, enter the remote access IP address you want to specify as logging host.
Step 5: Click Save.
Verify logging for connection events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.
Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.
Step 3: Click the edit icon next to a rule to view. Verify that a logging option has been selected. Verify that the Syslog check box has been selected.
---------------------------------------------------
Verify logging for Intrusion events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.
Step 2: Click Advanced Setting. The Advanced Settings page appears.
Step 3: Verify that Syslog Alerting under External Responses is enabled.
If the Cisco ASA is not configured to produce log records containing information to establish what type of event occurred, this is a finding.
V-239873
False
CASA-IP-000040
Verify logging for connection events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.
Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.
Step 3: Click the edit icon next to a rule to view. Verify that a logging option has been selected. Verify that the Syslog check box has been selected.
---------------------------------------------------
Verify logging for Intrusion events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.
Step 2: Click Advanced Setting. The Advanced Settings page appears.
Step 3: Verify that Syslog Alerting under External Responses is enabled.
If the Cisco ASA is not configured to produce log records containing information to establish what type of event occurred, this is a finding.
M
5341