1. Home
  2. Security Hardening
  3. CIS Cisco ASA 9.x Firewall L1 V1.0.0
  4. Ensure ‘local timezone’ is properly configured

Ensure ‘local timezone’ is properly configured

Details

Sets the local time zone information so that the time displayed by the ASA is more relevant to those who are viewing it.

Rationale:

Having a correct time set on a Cisco ASA is important for two main reasons. The first reason is that digital certificates compare this time to the range defined by their Valid From and Valid To fields to define a specific validity period. The second reason is to have a relevant time stamps when logging information. Whether you are sending messages to a syslog server, sending messages to an SNMP monitoring station, or performing packet captures, time stamps have little usefulness if you cannot be certain of their accuracy.

Solution

Step 1: Acquire standard zone name (enterprise_zone_name) used by the enterprise (GMT, UTC, EDT, PST)

Step 2: Run the following to configure the required value

hostname(config)# clock timezone

Default Value:

By default, the time zone is UTC

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Cisco.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles