01-07-2021 10:53 AM
Hi,
Im trying to configure a local password policy to fullfill a stig check but im unsure how to do it on an ASR.
On switches I have it normally goes like this:
But this isnt a supported method on an ASR. The googles isnt really halping me out on this one. Does nayone know how to do this?
Thanks for any help.
01-07-2021 01:46 PM
According to https://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/asr9k-r6-2/system-security/configuration/guide/b-system-security-cg-asr9000-62x/b-system-security-cg-asr9000-62x_chapter_010.html#concept_js2_ll3_jmb, it looks like the commands are:
aaa password-policy STIG-POLICY min-length 12 max-length 40 lifetime months 3 min-char-change 4 authen-max-attempts 5 lockout-time days 1 commit
Let me know if that worked since I don't have an ASR to verify these commands
01-19-2021 06:33 AM
Sorry I'm getting back to this late. But my ASR only has the command "aaa password restriction"
Thanks for your time.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide