SV-242617r714161_rule
V-242617
SRG-APP-000065-NDM-000214
CSCO-NM-000110
CAT II
10
Log in to the CLI via SSH or the console.
Configure using CLI to enable and configure lockout. After three failed login attempts, the account will be locked for 15 minutes.
Set accountlocking enable
Set accountlocking unlocktime 900
Log in to the CLI via SSH or the console. View the Cisco ISE configuration. Verify the following are set:
accountlocking enable
accountlocking unlocktime 900
If a lockout for local accounts is not configured, this is a finding.
V-242617
False
CSCO-NM-000110
Log in to the CLI via SSH or the console. View the Cisco ISE configuration. Verify the following are set:
accountlocking enable
accountlocking unlocktime 900
If a lockout for local accounts is not configured, this is a finding.
M
5384