STIGQter STIGQter: STIG Summary: Cisco ASA IPS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to log events based on policy access control rules, signatures, and anomaly analysis.

DISA Rule

SV-239878r665947_rule

Vulnerability Number

V-239878

Group Title

SRG-NET-000113-IDPS-00013

Rule Version

CASA-IP-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Deploy a Network Analysis policy.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.

Step 2: Click the edit icon next to the access control policy you want to edit. The access control policy editor appears.

Step 3: Click Advanced Settings. The access control policy advanced settings page appears.

Step 4: Click the edit icon next to Network Analysis and Intrusion Policies. The Network Analysis and Intrusion Policies pop-up window appears.

Step 5: Enable the Balanced Security and Connectivity or a site-customized policy.
-------------------------------------------------
Enable logging for connection events.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.

Step 2: Click the edit icon next to the access control policy you want to configure. The access control policy editor appears.

Step 3: Click the edit icon next to a rule to edit. Select a logging option either log at Beginning and End of Connection or log at End of Connection. Select the Syslog check box.

Step 4: Click Save.
---------------------------------------
Enable logging for Intrusion events.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.

Step 2: Click Advanced Settings. The Advanced Settings page appears.

Step 3: If Syslog Alerting under External Responses is enabled, click Edit. If the configuration is disabled, click Enabled, then click Edit. The Syslog Alerting page appears.

Step 4: in the Logging Hosts field, enter the remote access IP address you want to specify as logging host.

Step 5: Click Save.

Check Contents

Verify that a Network Analysis policy exists.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.

Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.

Step 3: Click Advanced Settings. The access control policy advanced settings page appears.

Step 4: Click the edit icon next to Network Analysis and Intrusion Policies. The Network Analysis and Intrusion Policies pop-up window appears.

Step 5: Click Network Analysis Policy List. The Network Analysis Policy List pop-up window appears.

Verify that a policy exists. By default, the system uses the Balanced Security and Connectivity network analysis policy.

Note: A network analysis policy governs how traffic is decoded and preprocessed so that it can be further evaluated for anomalous traffic that might signal an intrusion attempt. An intrusion policy uses intrusion and preprocessor rules (sometimes referred to collectively as intrusion rules) to examine the decoded packets for attacks based on patterns. Both network analysis and intrusion policies are invoked by a parent access control policy. As the system analyzes traffic, the network analysis phase occurs before and separately from the intrusion prevention phase.
-------------------------------------------------
Verify logging for connection events is enabled.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.

Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.

Step 3: Click the edit icon next to a rule to view. Verify that a logging option has been selected. Verify that the Syslog check box has been selected.
---------------------------------------------------
Verify logging for Intrusion events is enabled.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.

Step 2: Click Advanced Settings. The Advanced Settings page appears.

Step 3: Verify that Syslog Alerting under External Responses is enabled.

If the Cisco ASA is not configured to log events based on policy access control rules, signatures, and anomaly analysis, this is a finding.

Vulnerability Number

V-239878

Documentable

False

Rule Version

CASA-IP-000090

Severity Override Guidance

Verify that a Network Analysis policy exists.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.

Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.

Step 3: Click Advanced Settings. The access control policy advanced settings page appears.

Step 4: Click the edit icon next to Network Analysis and Intrusion Policies. The Network Analysis and Intrusion Policies pop-up window appears.

Step 5: Click Network Analysis Policy List. The Network Analysis Policy List pop-up window appears.

Verify that a policy exists. By default, the system uses the Balanced Security and Connectivity network analysis policy.

Note: A network analysis policy governs how traffic is decoded and preprocessed so that it can be further evaluated for anomalous traffic that might signal an intrusion attempt. An intrusion policy uses intrusion and preprocessor rules (sometimes referred to collectively as intrusion rules) to examine the decoded packets for attacks based on patterns. Both network analysis and intrusion policies are invoked by a parent access control policy. As the system analyzes traffic, the network analysis phase occurs before and separately from the intrusion prevention phase.
-------------------------------------------------
Verify logging for connection events is enabled.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.

Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.

Step 3: Click the edit icon next to a rule to view. Verify that a logging option has been selected. Verify that the Syslog check box has been selected.
---------------------------------------------------
Verify logging for Intrusion events is enabled.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.

Step 2: Click Advanced Settings. The Advanced Settings page appears.

Step 3: Verify that Syslog Alerting under External Responses is enabled.

If the Cisco ASA is not configured to log events based on policy access control rules, signatures, and anomaly analysis, this is a finding.

Check Content Reference

M

Target Key

5341