1.2.3 Limit SSH Login Attempts to 3 or less

Information

After a configured number of failed password attempts, an SSH session terminate. The default configuration for this is 3 failed attempts. CIS recommends using the default configuration for this setting.

This setting makes brute force and dictionary attacks against SSH more difficult.

Solution

switch(config)# ssh login attempts 3

Impact:

The default setting of 3 failed attempts is appropriate and does not need to be changed. However, in this default configuration this setting does not appear in the running or saved configuration. If it is important that this setting shows in the configuration this value can be modified.

See Also

https://workbench.cisecurity.org/benchmarks/16139

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|4.9, CSCv7|12.11

Plugin: Cisco

Control ID: 2924eada044320a9e903e6f534cc1de454fbf758cf63dc3545cca18f4bf588e3