1.4.3.2 Ensure 'aaa authentication http console' is configured correctly

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Authenticates ASDM users who access the security appliance over HTTP

Rationale:

By default, the enable password is used in combination with no username for http access. The aaa command is used to define the TACACS+/RADIUS authentication method. The local database can be mentioned as backup method to this primary method, failing that the ASDM will use the default administrator username and enabled password for authentication.

Solution

Configure the aaa authentication for http using the TACACS+ server-group as primary method and the local database as backup method.

HOSTNAME(CONFIG)#AAA AUTHENTICATION HTTP CONSOLE _<server-group_name_> LOCAL

See Also

https://workbench.cisecurity.org/files/1903

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: Cisco

Control ID: 7e0d89bbbfebbce7221067deaf35c76096c67dc89fd7128b7df76075f5f9c3ab