STIGUI
V-285612CAT II — Medium severitySV-285612r1273104_rule

The Content Analysis System (CAS) must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.

Rule version BCAS-ND-001110 · STIG v1 · 2026-09-16

Discussion

By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.

Check

Verify "local-lockout" is set to "max-failed-attempts 3", "lockout-duration 900", and "reset-interval 900" with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication" and review the output for the following exact settings: "local-lockout max-failed-attempts 3" "local-lockout lockout-duration 900" "local-lockout reset-interval 900"

If the values do not match exactly as specified above, this is a finding.

Fix

Configure "local-lockout" to "max-failed-attempts 3", "lockout-duration 900", and "reset-interval 900" with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the maximum failed attempts by entering "authentication local-lockout max-failed-attempts 3". 5. Set the lockout duration by entering "authentication local-lockout lockout-duration 900". 6. Set the reset interval by entering "authentication local-lockout reset-interval 900". 7. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285612
Group title
SRG-APP-000065-NDM-000214
Rule ID
SV-285612r1273104_rule
Check ID
C-90292r1272953_chk
Fix ID
F-90197r1272954_fix