- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2022 10:27 AM
Is there a way to configure the ASA 5555X to fail to a secure state upon a failure?
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2022 06:34 PM
I believe I have found the answer in another question in the community forum.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2022 10:43 AM
Failure can mean many things - from the box crashing to an interface going down to a bug causing certain traffic to be mishandled. Obviously if the former happens no traffic will pass through the device. I suppose you could call that "fail to a secure state".
We would need to know more about the context of your question to answer your original question better.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2022 11:00 AM
There is a DISA STIG that has the following requirement: The firewall must fail to a secure state upon the failure of the following: system initialization, shutdown, or system abort.
Thanks for the quick response.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2022 11:05 AM
The fix text says: Configure the firewall to stop forwarding traffic or maintain the configured security policies up the failure of the following actions: system initialization, shutdown, or system abort.
Could I create an EEM that shuts down ports incase of one of the actions? If so, what syslog id would I get the EEM to monitor?
Sorry for so many questions. This has been biting me for a long time now and I have to fix with a solution or they will have to accept a risk acceptance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2022 06:34 PM
I believe I have found the answer in another question in the community forum.
