SV-214672r1056079_rule
V-214672
SRG-NET-000062
JUSX-VN-000005
CAT I
10
The following example commands configure the IPsec (phase 2) proposals.
[edit]
set security ipsec proposal <IPSEC-PROPOSAL-NAME> encryption-algorithm aes-256-cbc
Verify all Internet Key Exchange (IKE) proposals are set to use the AES256 encryption algorithm.
[edit]
show security ipsec
View the value of the encryption algorithm for each defined proposal.
If the value of the encryption algorithm for any IPsec proposal is not set to use an AES256 algorithm, this is a finding.
V-214672
False
JUSX-VN-000005
Verify all Internet Key Exchange (IKE) proposals are set to use the AES256 encryption algorithm.
[edit]
show security ipsec
View the value of the encryption algorithm for each defined proposal.
If the value of the encryption algorithm for any IPsec proposal is not set to use an AES256 algorithm, this is a finding.
M
4009