STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN remote access server must be configured use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network.

DISA Rule

SV-207261r1138034_rule

Vulnerability Number

V-207261

Group Title

SRG-NET-000565

Rule Version

SRG-NET-000565-VPN-002390

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec VPN Gateway to use cryptography compliant with NSA/CSS parameters to protect NSS for remote access to a classified network.

Check Contents

Verify the VPN gateway is configured to use cryptography compliant with NSA/CSS parameters to protect NSS for remote access to a classified network.

If the VPN gateway is not configured to use cryptography compliant with NSA/CSS parameters to protect NSS for remote access to a classified network, this is a finding.

Vulnerability Number

V-207261

Documentable

False

Rule Version

SRG-NET-000565-VPN-002390

Severity Override Guidance

Verify the VPN gateway is configured to use cryptography compliant with NSA/CSS parameters to protect NSS for remote access to a classified network.

If the VPN gateway is not configured to use cryptography compliant with NSA/CSS parameters to protect NSS for remote access to a classified network, this is a finding.

Check Content Reference

M

Target Key

2920