SV-239948r878129_rule
V-239948
SRG-NET-000335-VPN-001270
CASA-VN-000090
CAT II
10
Configure the Cisco ASA to send critical to emergency log messages to the syslog server as shown in the example below.
ASA(config)# logging host NDM_INTERFACE 10.1.48.10 6/1514
ASA(config)# logging trap critical
ASA(config)# end
Note: The parameter "critical" can replaced with a lesser severity (i.e., error, warning, notice, informational). A logging list can be used as an alternative to the severity level.
Review the Cisco ASA configuration to verify that it is compliant with this requirement as shown in the example below.
logging trap critical
logging host NDM_INTERFACE 10.1.48.10 6/1514
Note: The parameter "critical" can replaced with a lesser severity (i.e., error, warning, notice, informational). A logging list can be used as an alternative to the severity level.
If the Cisco ASA is not configured to generate an alert that can be forwarded to organization-defined personnel and/or firewall administrator of all log failure events, this is a finding.
V-239948
False
CASA-VN-000090
Review the Cisco ASA configuration to verify that it is compliant with this requirement as shown in the example below.
logging trap critical
logging host NDM_INTERFACE 10.1.48.10 6/1514
Note: The parameter "critical" can replaced with a lesser severity (i.e., error, warning, notice, informational). A logging list can be used as an alternative to the severity level.
If the Cisco ASA is not configured to generate an alert that can be forwarded to organization-defined personnel and/or firewall administrator of all log failure events, this is a finding.
M
5344