STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA must be configured to use NIST FIPS-validated cryptography for Internet Key Exchange (IKE) Phase 1.

DISA Rule

SV-239953r916122_rule

Vulnerability Number

V-239953

Group Title

SRG-NET-000510-VPN-002180

Rule Version

CASA-VN-000170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to use NIST FIPS-validated cryptography for IKE Phase 1.

ASA1(config)# crypto ikev2 policy 1
ASA1(config-ikev2-policy)# encryption aes-256

Check Contents

Verify the ASA uses a NIST FIPS-validated cryptography for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1
encryption aes-256

If the ASA is not configured to use NIST FIPS-validated cryptography for IKE Phase 1, this is a finding.

Vulnerability Number

V-239953

Documentable

False

Rule Version

CASA-VN-000170

Severity Override Guidance

Verify the ASA uses a NIST FIPS-validated cryptography for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1
encryption aes-256

If the ASA is not configured to use NIST FIPS-validated cryptography for IKE Phase 1, this is a finding.

Check Content Reference

M

Target Key

5344