Rule ID
SV-255949r882189_rule
Version
V1R1
CCIs
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.
Verify the Arista device is configured to enforce the limit of three consecutive invalid logon attempts with the following command: switch#show running-config | section aaa aaa authentication policy lockout failure 3 duration 900 If the Arista device is not configured to enforce the limit of three consecutive invalid logon attempts, this is a finding.
Configure the account lockout policy using the following commands: switch(config)#aaa authentication policy lockout failure 3 switch(config)#duration 900 switch(config)#exit