cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
252
Views
0
Helpful
11
Replies

Security Config Parameter

duwijakarta
Level 2
Level 2

Hi everyone, I want to implement this on an firepower. Is it supported? It blocks logins for 360 seconds if there are 5 failures within 360 seconds.

1 Accepted Solution

Accepted Solutions

@duwijakarta not exactly, those are IOS/NXOS commands. You could use the configure user maxfailedlogins to lock the account after failed logins and the configure unlock_time command to automatically unlock after a set period.

https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/c_3.html#wp3584569324

 

View solution in original post

11 Replies 11

@duwijakarta not exactly, those are IOS/NXOS commands. You could use the configure user maxfailedlogins to lock the account after failed logins and the configure unlock_time command to automatically unlock after a set period.

https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/c_3.html#wp3584569324

 

Thank you @Rob Ingram , the answer is very helpful. Then, if I want to set a password, must it contain numbers and special characters? Is that possible or not?

@duwijakarta there does not look to be a password policy for local users, so in theory you could use whatever characters in the password.

@Rob Ingram ok, for previous reference is it the same as for the firepower 1140 ASA device not FTD

@duwijakarta the information and commands provided above are for FTD.

@Rob Ingram Is there any and can it be used for ASA type?

@Rob Ingram If I want to apply a user for read only and full access on the Firepower and Catalys 9200 devices, is that possible?

@duwijakarta 

Use radius to assign a user to administrator role (full access) or the security analysis (read only) role. Example:-

https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/221009-configure-fmc-and-ftd-external-authentic.html

Use TACACS+ (ISE) and assign the command set with the required level of permissions.

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html

 

@Rob Ingram thanks sir, If I make standard settings such as no AAA configuration or without radius or tacacs, can I create user types and requirements like that?

Review Cisco Networking for a $25 gift card