Check: CASA-VN-000080
Cisco ASA VPN STIG:
CASA-VN-000080
(in versions v1 r3 through v1 r1)
Title
The Cisco ASA must be configured to queue log records locally in the event that the central audit server is down or not reachable. (Cat II impact)
Discussion
If the system were to continue processing after audit failure, actions can be taken on the system that cannot be tracked and recorded for later forensic analysis. Because of the importance of ensuring mission/business continuity, organizations may determine that the nature of the audit failure is not so severe that it warrants a complete shutdown of the application supporting the core organizational missions/business operations. In those instances, partial application shutdowns or operating in a degraded mode with reduced capability may be viable alternatives. This requirement only applies to components where this is specific to the function of the device (e.g., IDPS sensor logs, firewall logs). This does not apply to audit logs generated on behalf of the device itself (management).
Check Content
If the ASA is configured to send syslog messages to a TCP-based syslog server, and if the syslog server is down new connections are blocked. To continue to allow new connections and queue log records verify that the logging permit-hostdown and the queue size has been increased (default is 512). logging enable … … … logging queue 8192 logging host NDM_INTERFACE 10.1.22.2 6/1514 logging permit-hostdown If the ASA is not configured to queue log records locally in the event that the central audit server is down or not reachable, this is a finding.
Fix Text
To continue to allow new connections and queue log records in the event the syslog server is not reachable, configure logging permit-hostdown and increase the queue size. ASA(config)# logging permit-hostdown ASA(config)# logging queue 8192
Additional Identifiers
Rule ID: SV-239947r856162_rule
Vulnerability ID: V-239947
Group Title: SRG-NET-000336-VPN-001280
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001861 |
The information system invokes an organization-defined system mode, in the event of organization-defined audit failures, unless an alternate audit capability exists. |
Controls
Number | Title |
---|---|
AU-5 (4) |
Shutdown On Failure |