Rule version BCAS-ND-001110 · STIG v1 · 2026-09-16
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.
Verify "local-lockout" is set to "max-failed-attempts 3", "lockout-duration 900", and "reset-interval 900" with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config authentication" and review the output for the following exact settings: "local-lockout max-failed-attempts 3" "local-lockout lockout-duration 900" "local-lockout reset-interval 900"
If the values do not match exactly as specified above, this is a finding.
Configure "local-lockout" to "max-failed-attempts 3", "lockout-duration 900", and "reset-interval 900" with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the maximum failed attempts by entering "authentication local-lockout max-failed-attempts 3". 5. Set the lockout duration by entering "authentication local-lockout lockout-duration 900". 6. Set the reset interval by entering "authentication local-lockout reset-interval 900". 7. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.