STIGQter STIGQter: STIG Summary: Juniper SRX Services Gateway VPN Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

The Juniper SRX Services Gateway VPN must use Internet Key Exchange (IKE) for IPsec VPN Security Associations (SAs).

DISA Rule

SV-214677r385561_rule

Vulnerability Number

V-214677

Group Title

SRG-NET-000512

Rule Version

JUSX-VN-000010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

The following example commands configure an IPsec VPN to use the IKE gateway information.

[edit]
set security ipsec vpn <VPN-GWY-NAME> ike gateway <IKE-PEER-NAME>

Check Contents

Verify the IKE protocol is specified for all IPsec VPNs.

[edit]
show security ipsec vpn

If the IKE protocol is not specified as an option on all VPN gateways, this is a finding.

Vulnerability Number

V-214677

Documentable

False

Rule Version

JUSX-VN-000010

Severity Override Guidance

Verify the IKE protocol is specified for all IPsec VPNs.

[edit]
show security ipsec vpn

If the IKE protocol is not specified as an option on all VPN gateways, this is a finding.

Check Content Reference

M

Target Key

4009

Comments