STIGQter STIGQter: STIG Summary: Cisco ASA IPS Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Cisco ASA must be configured to queue log records locally In the event that the central audit server is down or not reachable.

DISA Rule

SV-239881r665956_rule

Vulnerability Number

V-239881

Group Title

SRG-NET-000089-IDPS-00010

Rule Version

CASA-IP-000130

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Step 1: Navigate to Devices >> Platform Settings >> Syslog Servers.

Step 2: Click on the pencil icon to edit the applicable server.

Step 3: Select the TCP option.

Step 4: Click OK and Save.

Check Contents

Verify that TCP is being used to send log data to the syslog server.

Step 1: Navigate to Devices >> Platform Settings >> Syslog Servers.

Step 2: Verify that TCP is listed under the Protocol tab has been selected.

If the Cisco ASA is not configured to use TCP to send log data to the syslog server, this is a finding.

Vulnerability Number

V-239881

Documentable

False

Rule Version

CASA-IP-000130

Severity Override Guidance

Verify that TCP is being used to send log data to the syslog server.

Step 1: Navigate to Devices >> Platform Settings >> Syslog Servers.

Step 2: Verify that TCP is listed under the Protocol tab has been selected.

If the Cisco ASA is not configured to use TCP to send log data to the syslog server, this is a finding.

Check Content Reference

M

Target Key

5341