1.2.3 Limit SSH Login Attempts

Information

After a configured number of failed password attempts, an SSH session terminate. The default configuration for this is 3 failed attempts.

Rationale:

This setting makes brute force and dictionary attacks against SSH more difficult.

Impact:

In many environments, the default setting of 3 failed attempts is appropriate and does not need to be changed. However, in this default configuration this setting does not appear in the running or saved configuration. If it is important that this setting shows in the configuration this value can be modified.

Solution

switch(config)# ssh login attempts 3

Default Value:

By default, after 3 failed login attempts in an SSH session, that session is terminated.

See Also

https://workbench.cisecurity.org/benchmarks/6524

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|4.9, CSCv7|12.11

Plugin: Cisco

Control ID: 2924eada044320a9e903e6f534cc1de454fbf758cf63dc3545cca18f4bf588e3