STIGQter STIGQter: STIG Summary: Cisco ASA IPS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to off-load log records to a centralized log server.

DISA Rule

SV-239879r856155_rule

Vulnerability Number

V-239879

Group Title

SRG-NET-000334-IDPS-00191

Rule Version

CASA-IP-000110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Firepower to send log records to a syslog server as shown in the following steps:

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Actions Alerts.

Step 2: Click the Create Alert drop-down menu and choose option Create Syslog Alert.

Step 3: Enter the following values for the Syslog server:
Host: Specify the IP address/hostname of Syslog server.
Port: Specify the port number of Syslog server.

Step 4: Click Store ASA FirePOWER Changes.

Check Contents

Verify that a syslog server has been defined.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies > Actions Alerts. The Alerts page appears.

Step 2: Verify the IP address and port number of the syslog server.

If the Cisco ASA is not configured to send log records to a centralized log server, this is a finding.

Vulnerability Number

V-239879

Documentable

False

Rule Version

CASA-IP-000110

Severity Override Guidance

Verify that a syslog server has been defined.

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies > Actions Alerts. The Alerts page appears.

Step 2: Verify the IP address and port number of the syslog server.

If the Cisco ASA is not configured to send log records to a centralized log server, this is a finding.

Check Content Reference

M

Target Key

5341