4.3 Ensure 'Idle timeout' is less than or equal to 10 minutes for tmsh sessions

Information

To set an idel timeout for tmsh sessions

Solution

1.Log in to tmsh by typing the following command: tmsh
2.To configure an automatic logout idle time for tmsh sessions, use the following command syntax: modify /cli global-settings idle-timeout 10
3.Save the change by typing the following command: save /sys config

Impact:

Indefinite or even long session timeout window increases the risk of attackers abusing abandoned sessions.

See Also

https://workbench.cisecurity.org/files/3587

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: F5

Control ID: 0707e8d0e6bfcef8fe50179e25f00adc935047c647a7c15e8a7376700ba688b4