Rule version BCAS-ND-001330 · STIG v1 · 2026-09-16
Authentication for administrative (privileged level) access to the device is required at all times. An account can be created on the device's local database for use when the authentication server is down or connectivity between the device and the authentication server is not operable. This account is referred to as the account of last resort since it is intended to be used as a last resort and when immediate administrative access is absolutely necessary.
The account of last resort logon credentials must be stored in a sealed envelope and kept in a safe. The safe must be periodically audited to verify the envelope remains sealed. The signature of the auditor and the date of the audit should be added to the envelope as a record. Administrators should secure the credentials and disable the root account (if possible) when not needed for system administration functions.
Verify only one local account exists and the console-account is set to "fallback-only" with the following steps:
Verify local accounts via Web UI: 1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> Users >> Local Users. 3. Scroll down to the "Users" section and verify only the documented and approved account of last resort exists.
Verify fallback configuration via CLI: 1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config authentication". 3. Review the output for "authentication management console-account".
If any user other than the documented and approved local account of last resort exists, or if the console-account configuration states "always" instead of "fallback-only", this is a finding.
Configure the local account to "fallback-only" and remove all unauthorized local users with the following steps:
Remove unauthorized users via Web UI: 1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> Users >> Local Users. 3. Scroll down to the "Users" section. Note: Only the documented and approved account of last resort is permitted. 4. Delete all other local users by selecting the user, clicking "Delete User", and selecting "Yes" when prompted to confirm. 5. Click "Save Changes".
Configure fallback-only via CLI: 1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the console account to fallback-only by entering "authentication management console-account fallback-only". 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode. 6. To verify the change, attempt to log in with the local admin account while the external authentication server is reachable. It should prompt for a password but not permit successful login.