STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA must be configured to use Internet Key Exchange v2 (IKEv2) for all IPsec security associations.

DISA Rule

SV-239952r666262_rule

Vulnerability Number

V-239952

Group Title

SRG-NET-000132-VPN-000460

Rule Version

CASA-VN-000160

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IPsec VPN Gateway to use IKEv2 for all IPsec VPN Security Associations.

Step 1: Configure IKE for the IPsec Phase 1 policy and enable it on applicable interfaces.

ASA1(config)# crypto ikev2 policy 1
ASA1(config-ikev2-policy)# encryption …

ASA1(config)# crypto ikev2 enable OUTSIDE

Step 2: Configure IKE for the IPsec Phase 2.

ASA1(config)# crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS

Check Contents

Verify the ASA is configured to use IKEv2 for IPsec VPN security associations.

Step 1: Verify that IKE is configured for the IPsec Phase 1 policy and enabled on applicable interfaces.

crypto ikev2 policy 1
encryption …

crypto ikev2 enable OUTSIDE

Step 2: Verify that IKE is configured for the IPsec Phase 2.

crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption …

If the ASA is not configured to use IKEv2 for all IPsec VPN security associations, this is a finding.

Vulnerability Number

V-239952

Documentable

False

Rule Version

CASA-VN-000160

Severity Override Guidance

Verify the ASA is configured to use IKEv2 for IPsec VPN security associations.

Step 1: Verify that IKE is configured for the IPsec Phase 1 policy and enabled on applicable interfaces.

crypto ikev2 policy 1
encryption …

crypto ikev2 enable OUTSIDE

Step 2: Verify that IKE is configured for the IPsec Phase 2.

crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption …

If the ASA is not configured to use IKEv2 for all IPsec VPN security associations, this is a finding.

Check Content Reference

M

Target Key

5344