Ensure ‘Image Integrity’ is correct Details Verifies integrity of an uploaded software before upgrading the system Rationale: Sometimes, manipulating software from downloading them from the...
Ensure intrusion prevention is enabled for untrusted interfaces Details Enables the intrusion prevention with the IP audit feature on untrusted interfaces Rationale: The intrusion prevention is an additional...
Ensure ‘ip verify’ is set to ‘reverse-path’ for untrusted interfaces Details Enables the unicast Reverse-Path Forwarding (uRPF) on untrusted interfaces. Rationale: The unicast Reverse-Path Forwarding(uRPF) enabled on an interface ensures...
Ensure known default accounts do not exist Details Deletes the known default accounts configured Rationale: In order to attempt access to known devices’ platforms, attackers use the...
Ensure ‘logging’ is enabled Details Enables logging Rationale: Logging is fundamental for audit requirements and incident management and should be enabled on any business...
Ensure ‘logging to Serial console’ is disabled Details Disables the logging to the Serial console Rationale: Enabling the logs to be sent to the Serial console may...
Ensure ‘logging buffer size’ is greater than or equal to ‘524288’ bytes (512kb) Details Determines the size of the local buffer in which the logs are stored so that they can be checked...
Ensure ‘logging trap severity ‘ is greater than or equal to ‘5’ Details Determines which syslog messages should be sent to the syslog server. Rationale: Syslog messages are an invaluable tool for...
Ensure non-default application inspection is configured correctly Details Enables the inspection of an application that is not in the default global policy application inspection Rationale: By default,...
Ensure ‘noproxyarp’ is enabled for untrusted interfaces Details Disables the Proxy-ARP function on untrusted interfaces Rationale: The Firepower replies to ARP requests performed to IP addresses belonging...