UCF STIG Viewer Logo

The firewall implementation must be configured to use two or more authentication servers for the purpose of granting administrative access.


Overview

Finding ID Version Rule ID IA Controls Severity
V-37337 SRG-NET-999999-FW-000167 SV-49098r1_rule Medium
Description
The use of an authentication server affords the best methods for controlling user access, authorization levels, and activity logging. By enabling an authentication server, the administrators can easily add or remove user accounts; add or remove command authorizations; and maintain a log of user activity. The use of an authentication server provides the capability to assign router administrators to tiered groups that contain their privilege levels that are used for authorization of specific commands. For example, user mode would be authorized for all authenticated administrators while configuration or edit mode should only be granted to those administrators that are permitted to implement router configuration changes.
STIG Date
Firewall Security Requirements Guide 2013-04-24

Details

Check Text ( C-45585r1_chk )
Verify an authentication server is required to access the device.
Verify there are two or more authentication servers defined.

If the firewall is not configured to use two or more authentication servers, this is a finding.
Fix Text (F-42262r1_fix)
Configure the firewall implementation to use an authentication server to access the device, so there are two or more authentication servers defined.