SV-239932r961620_rule
V-239932
SRG-APP-000435-NDM-000315
CASA-ND-001180
CAT II
10
Configure the Cisco ASA to protect against known types of DoS attacks by enabling the Threat Detection feature.
ASA(config)# threat-detection basic-threat
ASA(config)# end
Note: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled, and this check is Not Applicable.
Review the ASA configuration and verify the Threat Detection feature is enabled as shown in the example below.
threat-detection basic-threat
If the Cisco ASA does not have the Threat Detection feature enabled, this is a finding.
V-239932
False
CASA-ND-001180
Note: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled, and this check is Not Applicable.
Review the ASA configuration and verify the Threat Detection feature is enabled as shown in the example below.
threat-detection basic-threat
If the Cisco ASA does not have the Threat Detection feature enabled, this is a finding.
M
5342