SV-220576r521267_rule
V-220576
SRG-APP-000065-NDM-000214
CISC-ND-000150
CAT II
10
Configure the Cisco switch to enforce the limit of three consecutive invalid logon attempts as shown in the example below:
SW2(config)#login block-for 900 attempts 3 within 120
Review the Cisco switch configuration to verify that it enforces the limit of three consecutive invalid logon attempts as shown in the example below:
login block-for 900 attempts 3 within 120
Note: The configuration example above will block any logon attempt for 15 minutes after three consecutive invalid logon attempts within a two-minute period.
If the Cisco switch is not configured to enforce the limit of three consecutive invalid logon attempts, this is a finding.
V-220576
False
CISC-ND-000150
Review the Cisco switch configuration to verify that it enforces the limit of three consecutive invalid logon attempts as shown in the example below:
login block-for 900 attempts 3 within 120
Note: The configuration example above will block any logon attempt for 15 minutes after three consecutive invalid logon attempts within a two-minute period.
If the Cisco switch is not configured to enforce the limit of three consecutive invalid logon attempts, this is a finding.
M
4069