Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-37337 | SRG-NET-999999-FW-000167 | SV-49098r1_rule | Medium |
Description |
---|
The use of an authentication server affords the best methods for controlling user access, authorization levels, and activity logging. By enabling an authentication server, the administrators can easily add or remove user accounts; add or remove command authorizations; and maintain a log of user activity. The use of an authentication server provides the capability to assign router administrators to tiered groups that contain their privilege levels that are used for authorization of specific commands. For example, user mode would be authorized for all authenticated administrators while configuration or edit mode should only be granted to those administrators that are permitted to implement router configuration changes. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2013-04-24 |
Check Text ( C-45585r1_chk ) |
---|
Verify an authentication server is required to access the device. Verify there are two or more authentication servers defined. If the firewall is not configured to use two or more authentication servers, this is a finding. |
Fix Text (F-42262r1_fix) |
---|
Configure the firewall implementation to use an authentication server to access the device, so there are two or more authentication servers defined. |