STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN gateway must use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.

DISA Rule

SV-207262r1138037_rule

Vulnerability Number

V-207262

Group Title

SRG-NET-000565

Rule Version

SRG-NET-000565-VPN-002400

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec VPN Gateway IKE to use cryptography compliant with NSA/CSS parameters when transporting classified traffic across an unclassified network.

Check Contents

Verify the VPN gateway Internet Key Exchange (IKE) Phase 1 and Phase 2 are configured to use cryptography compliant with NSA/CSS parameters when transporting classified traffic across an unclassified network.

If the VPN gateway is not configured to use cryptography compliant with NSA/CSS parameters when transporting classified traffic across an unclassified network, this is a finding.

Vulnerability Number

V-207262

Documentable

False

Rule Version

SRG-NET-000565-VPN-002400

Severity Override Guidance

Verify the VPN gateway Internet Key Exchange (IKE) Phase 1 and Phase 2 are configured to use cryptography compliant with NSA/CSS parameters when transporting classified traffic across an unclassified network.

If the VPN gateway is not configured to use cryptography compliant with NSA/CSS parameters when transporting classified traffic across an unclassified network, this is a finding.

Check Content Reference

M

Target Key

2920