STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The IPsec VPN Gateway must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation.

DISA Rule

SV-207244r916233_rule

Vulnerability Number

V-207244

Group Title

SRG-NET-000371

Rule Version

SRG-NET-000371-VPN-001640

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec VPN Gateway to specify PFS during IKE negotiation.

Check Contents

Verify the IPsec VPN Gateway specifies PFS during IKE negotiation.

If the IPsec VPN Gateway does not specify PFS during IKE negotiation, this is a finding.

Vulnerability Number

V-207244

Documentable

False

Rule Version

SRG-NET-000371-VPN-001640

Severity Override Guidance

Verify the IPsec VPN Gateway specifies PFS during IKE negotiation.

If the IPsec VPN Gateway does not specify PFS during IKE negotiation, this is a finding.

Check Content Reference

M

Target Key

2920