Setting a Login Failure Blocking Period
With this IOS login enhancement command, available in Cisco IOS software Release 12.3(4)T and later, the IOS router will not accept any additional login connections for a "quiet period" if the configured number of connection attempts fail within a specified time period. Hosts that are permitted by a predefined ACL are excluded from the quiet period. You can specify the predefined ACL that is excluded from the quiet period by using the global configuration mode command login quiet-mode access-class.
The first command parameter (seconds) specifies the duration of time, or quiet period, during which login attempts are denied.
The second parameter (attempts) stands for the maximum number of failed login attempts that triggers the quiet period.
The third parameter (within) describes the duration of time, in seconds, during which the allowed number of failed login attempts must be made before the quiet period is triggered.
After the login block-for command is enabled, these defaults are enforced:
■ A default login delay of one second.
■ All login attempts made via Telnet, secure shell (SSH), and HTTP are denied during the quiet period; that is, no ACLs are exempt from the login period until the login quiet-mode access-class command is issued.
System Logging Messages for a Quiet Period
After a router switches to and from quiet mode, logging messages are generated. Also, if configured, logging messages are generated upon every successful or failed login request. Logging messages can be generated for successful login requests via the new global configuration command login on-success. The login on-failure command generates logs for failed login requests.
5-100 Implementing Secure Converged Wide Area Networks (ISCW) v1.0
This logging message is generated after the router switches to quiet-mode:
00:04:07:%SEC_LOGIN-1-QUIET_MODE_ON:Still timeleft for watching failures is 158 seconds, [user:sfd] [Source:10.4.2.11] [localport:23] [Reason:Invalid login], [ACL:22] at 16:17:23 UTC Wed Feb 26 2003
The following logging message is generated after the router switches from quiet mode back to normal mode:
00:09:07:%SEC_LOGIN-5-QUIET_MODE_OFF:Quiet Mode is OFF, because block period timed out at 16:22:23 UTC Wed Feb 26 2003
© 2006 Cisco Systems, Inc. Cisco Device Hardening 5-101
Continue reading here: Configuring Superviews
Was this article helpful?