STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The IPsec VPN must use AES256 or greater encryption for the IPsec proposal to protect the confidentiality of remote access sessions.

DISA Rule

SV-207257r916158_rule

Vulnerability Number

V-207257

Group Title

SRG-NET-000525

Rule Version

SRG-NET-000525-VPN-002330

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec Gateway to use AES256 or greater for the IPsec proposal.

Check Contents

Verify all Internet Key Exchange (IKE) proposals are set to use the AES256 or greater encryption algorithm.

View the value of the encryption algorithm for each defined proposal.

If the value of the encryption algorithm for any IPsec proposal is not set to use an AES256 or greater algorithm, this is a finding.

Vulnerability Number

V-207257

Documentable

False

Rule Version

SRG-NET-000525-VPN-002330

Severity Override Guidance

Verify all Internet Key Exchange (IKE) proposals are set to use the AES256 or greater encryption algorithm.

View the value of the encryption algorithm for each defined proposal.

If the value of the encryption algorithm for any IPsec proposal is not set to use an AES256 or greater algorithm, this is a finding.

Check Content Reference

M

Target Key

2920