1.4.3.2 Ensure 'aaa authentication http console' is configured correctly

Information

Authenticates ASDM users who access the security appliance over HTTP

Rationale:

By default, the enable password is used in combination with no username for http access. The aaa command is used to define the TACACS+/RADIUS authentication method. The local database can be mentioned as backup method to this primary method, failing that the ASDM will use the default administrator username and enabled password for authentication.

Solution

Configure the aaa authentication for http using the TACACS+ server-group as primary method and the local database as backup method.

hostname(config)#aaa authentication http console <server-group_name> local

Default Value:

The http aaa authentication is disabled by default.

See Also

https://workbench.cisecurity.org/files/3294

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(9), CSCv7|4.3

Plugin: Cisco

Control ID: 5db0def2670813df7f62e8ba91b00c6a3f50eee0524c0d25f395d5739dbf6a62