STIGQter STIGQter: STIG Summary: Cisco ASA IPS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to send log records to the syslog server for specific facility and severity level.

DISA Rule

SV-239880r665953_rule

Vulnerability Number

V-239880

Group Title

SRG-NET-000113-IDPS-00189

Rule Version

CASA-IP-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Actions Alerts.

Step 2: Click the Create Alert drop-down menu and choose option Create Syslog Alert.

Step 3: Enter the following values for the Syslog server:
Facility: Select any facility that is configured on your Syslog server.
Severity: Select any severity that is configured on your Syslog server.

Step 4: Click Store ASA FirePOWER Changes.

Check Contents

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Actions Alerts. The Alerts page appears.

Step 2: Verify a facility has been selected for the syslog server.

If the Cisco ASA Firepower is not configured to send log records to the syslog server for specific facility and severity level, this is a finding.

Vulnerability Number

V-239880

Documentable

False

Rule Version

CASA-IP-000120

Severity Override Guidance

Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Actions Alerts. The Alerts page appears.

Step 2: Verify a facility has been selected for the syslog server.

If the Cisco ASA Firepower is not configured to send log records to the syslog server for specific facility and severity level, this is a finding.

Check Content Reference

M

Target Key

5341