08-16-2016 11:19 PM - edited 03-12-2019 01:08 AM
Hi Experts,
I would like to inquire if we could configure a minimum password length in Cisco firewall service module Cisco FWSM?
this is to ordain our admins whenever they were creating a user with the password; they will always be required to enter the minimum of 8 characters/alphanumeric set.
Searched the whole afternoon on this topic but there was no specific info found online.
ASA has their password policy attributes, link below.
however negative to find its FWSM counter-part.
Cheers!
Norix S.
Solved! Go to Solution.
08-16-2016 11:37 PM
As you mention, the ASA got these password-policies. But the FWSM-software is EOL and didn't get new features for a long time. It's time to think about a replacement for this module.
08-16-2016 11:42 PM
Hi Bro
Yes, the Cisco FWSM doesn’t have the minimum password length feature, compared to Cisco ASA. You must understand, the technology behind Cisco FWSM, came from Cisco PIX. Hence, you cannot compare apple-to-apple between Cisco FWSM and Cisco ASA or even Cisco ASASM, as Cisco ASA or even Cisco ASASM features are a lot more now, and is very matured.
Alternatively, you could integrate the Cisco FWSM with an Authentication Server e.g. Cisco ACS (TACACS+), Windows AD (LDAP) etc. and enforce the minimum length password policy in these Authentication Server.
Mind you, Cisco doesn’t support Cisco FWSM now. If I were you, it’s good to upgrade to Cisco ASASM.
Good luck sir!
08-16-2016 11:37 PM
As you mention, the ASA got these password-policies. But the FWSM-software is EOL and didn't get new features for a long time. It's time to think about a replacement for this module.
08-16-2016 11:49 PM
Karsten
appreciate your advise on this.
very helpful indeed!
thanks!
08-16-2016 11:42 PM
Hi Bro
Yes, the Cisco FWSM doesn’t have the minimum password length feature, compared to Cisco ASA. You must understand, the technology behind Cisco FWSM, came from Cisco PIX. Hence, you cannot compare apple-to-apple between Cisco FWSM and Cisco ASA or even Cisco ASASM, as Cisco ASA or even Cisco ASASM features are a lot more now, and is very matured.
Alternatively, you could integrate the Cisco FWSM with an Authentication Server e.g. Cisco ACS (TACACS+), Windows AD (LDAP) etc. and enforce the minimum length password policy in these Authentication Server.
Mind you, Cisco doesn’t support Cisco FWSM now. If I were you, it’s good to upgrade to Cisco ASASM.
Good luck sir!
08-16-2016 11:48 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide