1.4.3.1 Ensure 'aaa authentication enable console' is configured correctly

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Authenticates users trying to access the Enable mode (privileged EXEC mode) through the 'enable' command.

Rationale:

The default access to enable mode is done through a password. AAA provides a primary method for authenticating users (a username/password database stored on a TACACS+ or RADIUS server or group of servers) and then specifies backup method (a locally stored username/password database). The backup method is used if the primary method's database cannot be accessed by the networking device.

Solution

Configure the aaa authentication for enable access using the TACACS+ server-group as primary method and the local database as backup method

HOSTNAME(CONFIG)# AAA AUTHENTICATION ENABLE CONSOLE <_server-group_name_> LOCAL

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Cisco

Control ID: 017ca146f249270c0c6bdce6b975e8f7648d437214e17e8e4333a87ecfd0e807