STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA VPN remote access server must be configured to generate log records when successful and/or unsuccessful VPN connection attempts occur.

DISA Rule

SV-239983r666355_rule

Vulnerability Number

V-239983

Group Title

SRG-NET-000492-VPN-001980

Rule Version

CASA-VN-000720

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to generate log records when successful and/or unsuccessful VPN connection attempts occur as shown in the example below.

ASA2(config)# logging class svc trap notifications

Check Contents

Verify the ASA generates log records when successful and/or unsuccessful VPN connection attempts occur as shown in the example below.

logging host INDM_INTERFACE 10.1.1.12
logging class svc trap notifications

Note: A logging list can be used as an alternative to using class.

If the ASA does not generate log records when successful and/or unsuccessful VPN connection attempts occur, this is a finding.

Vulnerability Number

V-239983

Documentable

False

Rule Version

CASA-VN-000720

Severity Override Guidance

Verify the ASA generates log records when successful and/or unsuccessful VPN connection attempts occur as shown in the example below.

logging host INDM_INTERFACE 10.1.1.12
logging class svc trap notifications

Note: A logging list can be used as an alternative to using class.

If the ASA does not generate log records when successful and/or unsuccessful VPN connection attempts occur, this is a finding.

Check Content Reference

M

Target Key

5344