STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The IPSec VPN must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1.

DISA Rule

SV-207193r916149_rule

Vulnerability Number

V-207193

Group Title

SRG-NET-000074

Rule Version

SRG-NET-000074-VPN-000250

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec VPN to use the DH Group of 16 or greater for IKE Phase 1.

Check Contents

Verify all IKE proposals are set to use DH Group of 16 or greater for IKE Phase 1.

View the IKE options dh-group option.

If the IKE option is not set to use DH Group of 16 or greater for IKE Phase 1, this is a finding.

Vulnerability Number

V-207193

Documentable

False

Rule Version

SRG-NET-000074-VPN-000250

Severity Override Guidance

Verify all IKE proposals are set to use DH Group of 16 or greater for IKE Phase 1.

View the IKE options dh-group option.

If the IKE option is not set to use DH Group of 16 or greater for IKE Phase 1, this is a finding.

Check Content Reference

M

Target Key

2920