2.1.1.1.5 Set maximimum value for 'ip ssh authentication-retries'

Information

The number of retries before the SSH login session disconnects.

Rationale:

This limits the number of times an unauthorized user can attempt a password without having to establish a new SSH login attempt. This reduces the potential for success during online brute force attacks by limiting the number of login attempts per SSH connection.

Impact:

Organizations should implement a security policy limiting the number of authentication attempts for network administrators and enforce the policy through the 'ip ssh authentication-retries' command.

Solution

Configure the SSH timeout:

hostname(config)#ip ssh authentication-retries [<em>3</em>]

Default Value:

SSH is not enabled by default. When set, the default value is 3.

See Also

https://workbench.cisecurity.org/files/3829

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-18, 800-53|SC-23, CSCv7|5.1

Plugin: Cisco

Control ID: dcc056c0ac10e3fd48159e6754117963f4ac471a028f653619108956fa8cdc79