SV-239954r916233_rule
V-239954
SRG-NET-000371-VPN-001640
CASA-VN-000180
CAT II
10
Configure the ASA to specify PFS for the IPsec SA during IKE Phase 2 negotiation as shown in the example below.
ASA3(config)# crypto map IPSEC_CRYPTO_MAP 1 set pfs group5
Review crypto maps that reference an IPsec proposal. Verify the ASA is configured to specify PFS as shown in the example below.
crypto map IPSEC_CRYPTO_MAP 1 set pfs group5
crypto map IPSEC_CRYPTO_MAP 1 set peer x.x.x.x
crypto map IPSEC_CRYPTO_MAP 1 set ikev2 ipsec-proposal IPSEC_TRANS
If the ASA is not configured to specify PFS for the IPsec SA during IKE Phase 2 negotiation, this is a finding.
V-239954
False
CASA-VN-000180
Review crypto maps that reference an IPsec proposal. Verify the ASA is configured to specify PFS as shown in the example below.
crypto map IPSEC_CRYPTO_MAP 1 set pfs group5
crypto map IPSEC_CRYPTO_MAP 1 set peer x.x.x.x
crypto map IPSEC_CRYPTO_MAP 1 set ikev2 ipsec-proposal IPSEC_TRANS
If the ASA is not configured to specify PFS for the IPsec SA during IKE Phase 2 negotiation, this is a finding.
M
5344