SV-220579r521267_rule
V-220579
SRG-APP-000091-NDM-000223
CISC-ND-000250
CAT II
10
Configure the Cisco switch to log all logon attempts as shown in the example below:
SW1(config)#login on-failure log
SW1(config)#login on-success log
SW1(config)#end
Review the Cisco switch configuration to verify that it generates audit records of all logon attempts. The configuration example below will log all logon attempts:
login on-failure log
login on-success log
If the Cisco switch is not configured to generate audit records of successful/unsuccessful attempts to log on, this is a finding.
V-220579
False
CISC-ND-000250
Review the Cisco switch configuration to verify that it generates audit records of all logon attempts. The configuration example below will log all logon attempts:
login on-failure log
login on-success log
If the Cisco switch is not configured to generate audit records of successful/unsuccessful attempts to log on, this is a finding.
M
4069