Skip to content

Cisco ASA Firewall Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Cisco ASA perimeter firewall must be configured to block all outbound management traffic.

    <VulnDiscussion>The management network must still have its own subnet in order to enforce control and access boundaries provided by Layer 3 n...
    Rule Medium Severity
  • SRG-NET-000364-FW-000036

    <GroupDescription></GroupDescription>
    Group
  • The Cisco ASA must be configured to forward management traffic to the Network Operations Center (NOC) via an IPsec tunnel.

    &lt;VulnDiscussion&gt;When the production network is managed in-band, the management network could be housed at a NOC that is located remotely at s...
    Rule Medium Severity
  • SRG-NET-000364-FW-000040

    <GroupDescription></GroupDescription>
    Group
  • The Cisco ASA must be configured to inspect all inbound and outbound traffic at the application layer.

    &lt;VulnDiscussion&gt;Application inspection enables the firewall to control traffic based on different parameters that exist within the packets su...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules