ONTAP must be configured to limit the number of concurrent sessions.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-246922SRG-APP-000001-NDM-000200NAOT-AC-000001SV-246922r960735_rule2024-08-222
Description
Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administrator based on account type, role, or access type is helpful in limiting risks related to DoS attacks.
ℹ️ Check
Use "security session limit show -interface cli" to check the concurrent session limit. If the security session limit is not configured to limit the number of concurrent sessions to 1, this is a finding.
✔️ Fix
Configure session limits with the command, “security session limit modify -max-active-limit 1 -interface cli -category application".