1.8.3 Ensure 'HTTP session timeout' is less than or equal to '5' minutes

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sets the timeout for an HTTP session before the security appliance terminates it.

Rationale:

Limiting session timeout prevents unauthorized users from using abandoned sessions to perform malicious activities.

Solution

* Step 1: Run the following to set the HTTP timeout to less than or equal to 5 minutes

HOSTNAME(CONFIG)# HTTP SERVER SESSION-TIMEOUT_ 5_

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf