1.2.8 Set 'exec-timeout' less than or equal to 10 minutes 'line tty'

Information

If no input is detected during the interval, the EXEC facility resumes the current connection. If no connections exist, the EXEC facility returns the terminal to the idle state and disconnects the incoming session.

Solution

Configure device timeout (10 minutes or less) to disconnect sessions after a fixed idle time.
hostname(config)#line tty {line_number} [ending_line_number]
hostname(config-line)#exec-timeout <timeout_in_minutes> <timeout_in_seconds>

See Also

https://workbench.cisecurity.org/files/508

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12

Plugin: Cisco

Control ID: be33bb5d431f29f48e801c5e50a63135ba86a93e7a8e8f71813470789ff8bfec