STIGQter STIGQter: STIG Summary: Juniper SRX Services Gateway VPN Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 30 Jan 2025:

The Juniper SRX Services Gateway VPN Internet Key Exchange (IKE) must be configured to use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network.

DISA Rule

SV-214690r1056094_rule

Vulnerability Number

V-214690

Group Title

SRG-NET-000352

Rule Version

JUSX-VN-000023

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Navigate to the IKE proposal stanza.

Example stanza.
[edit]
set security ike proposal <name-proposal>
set ike proposal <name-proposal> authentication-method ecdsa-signatures-384
set ike proposal <name-proposal> dh-group group20
set ike proposal <name-proposal> authentication-algorithm sha-384
set ike proposal <name-proposal> encryption-algorithm aes-256-cbc

Check Contents

If the device is not used to transport classified traffic across an unclassified network, this is not applicable.

[edit]
show security ike <suiteb-proposal-name>

View the configured options.

If the IKE proposal encryption algorithms are not configured in compliance with CSfC, this is a finding.

Vulnerability Number

V-214690

Documentable

False

Rule Version

JUSX-VN-000023

Severity Override Guidance

If the device is not used to transport classified traffic across an unclassified network, this is not applicable.

[edit]
show security ike <suiteb-proposal-name>

View the configured options.

If the IKE proposal encryption algorithms are not configured in compliance with CSfC, this is a finding.

Check Content Reference

M

Target Key

4009