07-25-2018 02:30 PM - edited 02-21-2020 08:01 AM
I need to know for a client if the Cisco ASA 5506-X Network Security Firewall with Security Plus License is compliant with this security question:
Does the agency ensure that boundary protection devices do not release unauthorized information if a failure occurs (the device should "fails closed" versus "fails open")?
Thank you.
07-25-2018 06:46 PM
Hi,
AFAIK there is no definitive answer for your client. This this depends on multiple factors like how the device is configured, what traffic permitted, what encryption used, how it is administered (software updates etc) and so on. A failure can be different ways. As you are well aware- if there its power failure - the fail close and all traffic will be blocked. Any network device can protect upto certain extent and it is recommended to implement multi layer protection at perimeter.
hth
MS
07-25-2018 10:17 PM
What is their definition of "failure" was this elaborated? if not, its impossible to answer the question.
07-26-2018 10:26 AM
07-26-2018 01:23 PM
Hi,
You can tell client incase of power failure - its fail close. You may hear back from them with more color to the question.
hth
MS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide