1.4.1.2 Ensure 'local username and password' is set

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sets a local username and password

Rationale:

Default device configuration does not require strong user authentication enabling unfettered access to an attacker that can reach the device. Creating a local account with a strong password enforces login authentication and provides a fallback authentication mechanism in case remote centralized authentication, authorization and accounting services are unavailable

Solution

Run the following to set a local username and password.

HOSTNAME(CONFIG)#USERNAME _<local_username>_ PASSWORD _<local_password>_ PRIVILEGE _<level> _

The privilege level is chosen between 0 and 15. If the privilege is not configured, the default one is 2.

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, 800-53|IA-5

Plugin: Cisco

Control ID: 44ecaa02bb7496e3b59855f49ccf354739973885b60ad4672ed86299466b7492