STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The IPSec VPN must be configured to use FIPS-validated SHA-2 at 384 bits or higher for Internet Key Exchange (IKE).

DISA Rule

SV-207223r916152_rule

Vulnerability Number

V-207223

Group Title

SRG-NET-000230

Rule Version

SRG-NET-000230-VPN-000780

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec VPN Gateway to use IKE with SHA-2 at 384 bits or greater to protect the authenticity of communications sessions.

Check Contents

Verify the IPsec VPN Gateway uses IKE with SHA-2 at 384 bits or greater to protect the authenticity of communications sessions.

If the IPsec VPN Gateway is not configured to use IKE with SHA-2 at 384 bits or greater to protect the authenticity of communications sessions, this is a finding.

Vulnerability Number

V-207223

Documentable

False

Rule Version

SRG-NET-000230-VPN-000780

Severity Override Guidance

Verify the IPsec VPN Gateway uses IKE with SHA-2 at 384 bits or greater to protect the authenticity of communications sessions.

If the IPsec VPN Gateway is not configured to use IKE with SHA-2 at 384 bits or greater to protect the authenticity of communications sessions, this is a finding.

Check Content Reference

M

Target Key

2920