1.6.5 Ensure 'Telnet' is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disables the telnet access to the security appliance in the case it has been configured

Rationale:

Telnet is an unsecure protocol as username and password are conveyed in clear text during the administrator authentication and can be retrieved through network sniffing.

Solution

* Step 1: Run the following to remove the telnet access

HOSTNAME(CONFIG)#NO TELNET 0.0.0.0 0.0.0.0 _<interface_name>_

* Step 2: Run the following to remove the configured telnet timeout

HOSTNAME(CONFIG)#NO TELNET TIMEOUT _<configured_timeout>_

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Cisco

Control ID: 90d8615030d73aa96151f098a5689c852fc225f3c06ce4b41395e7b5c62b3e48