<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Locking down ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124228#M392260</link>
    <description>&lt;P&gt;I am working on locking down the ASA and I am looking for the commands to set the number of failed authentications before it won't accept login attempts from that host.&amp;nbsp; I found a single command to set the max times but what about the max duration or the time between attempts settings.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:51:35 GMT</pubDate>
    <dc:creator>bob.bartlett</dc:creator>
    <dc:date>2019-03-12T00:51:35Z</dc:date>
    <item>
      <title>Locking down ASA</title>
      <link>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124228#M392260</link>
      <description>&lt;P&gt;I am working on locking down the ASA and I am looking for the commands to set the number of failed authentications before it won't accept login attempts from that host.&amp;nbsp; I found a single command to set the max times but what about the max duration or the time between attempts settings.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124228#M392260</guid>
      <dc:creator>bob.bartlett</dc:creator>
      <dc:date>2019-03-12T00:51:35Z</dc:date>
    </item>
    <item>
      <title>Locking down ASA</title>
      <link>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124229#M392263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say there is no such a comand on the ASA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can set after how much idle time a user will need to reauthenticate but that's it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout &lt;SPAN style="font-size: 10pt;"&gt;uauth&amp;nbsp; xx:xx:xx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 04:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124229#M392263</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-24T04:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Locking down ASA</title>
      <link>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124230#M392266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For full control of the login-environment, you should use a TACACS- or RADIUS-Server. There you can configure the parameters as you want.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 06:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124230#M392266</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-24T06:34:13Z</dc:date>
    </item>
    <item>
      <title>Locking down ASA</title>
      <link>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124231#M392269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have it locked down there but if the TACACS fails then their is nothing to prevent a dictionary attack.&amp;nbsp; So how to you prevent that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 15:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124231#M392269</guid>
      <dc:creator>bob.bartlett</dc:creator>
      <dc:date>2013-01-24T15:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Locking down ASA</title>
      <link>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124232#M392271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing is the max-fail you already mentioned. And then you can configure a password-policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;asa1(config)# password-policy ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;configure mode commands/options:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; authenticate-enable&amp;nbsp; Enable the user authentication feature&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; lifetime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set password lifetime&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; minimum-changes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set minimum character changes between old and new&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; password&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; minimum-length&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set minimum password length&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; minimum-lowercase&amp;nbsp;&amp;nbsp;&amp;nbsp; Set minimum number of lowercase password characters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; minimum-numeric&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set minimum number of numeric password characters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; minimum-special&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set minimum number of special password characters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; minimum-uppercase&amp;nbsp;&amp;nbsp;&amp;nbsp; Set minimum number of uppercase password characters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's from an 8.4.4 ASA.&amp;nbsp; But that is gone on my v9.1-ASA (not sure if it's only a bug, RSA-authentication also doesn't work any more):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;asa(config)# password-policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ERROR: % Invalid input detected at '^' marker.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 15:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/locking-down-asa/m-p/2124232#M392271</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-24T15:32:27Z</dc:date>
    </item>
  </channel>
</rss>

