SV-239953r916122_rule
V-239953
SRG-NET-000510-VPN-002180
CASA-VN-000170
CAT II
10
Configure the ASA to use NIST FIPS-validated cryptography for IKE Phase 1.
ASA1(config)# crypto ikev2 policy 1
ASA1(config-ikev2-policy)# encryption aes-256
Verify the ASA uses a NIST FIPS-validated cryptography for IKE Phase 1 as shown in the example below.
crypto ikev2 policy 1
encryption aes-256
If the ASA is not configured to use NIST FIPS-validated cryptography for IKE Phase 1, this is a finding.
V-239953
False
CASA-VN-000170
Verify the ASA uses a NIST FIPS-validated cryptography for IKE Phase 1 as shown in the example below.
crypto ikev2 policy 1
encryption aes-256
If the ASA is not configured to use NIST FIPS-validated cryptography for IKE Phase 1, this is a finding.
M
5344