SV-239956r916128_rule
V-239956
SRG-NET-000510-VPN-002170
CASA-VN-000200
CAT II
10
Configure the ASA to use a FIPS-validated cryptographic module to implement IPsec encryption services as shown in the example below.
ASA2(config)# crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
ASA2(config-ipsec-proposal)# protocol esp encryption aes-256
Verify the ASA uses a FIPS-validated cryptographic module to implement IPsec encryption services.
crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption aes-256
If the ASA is not configured to use a FIPS-validated cryptographic module to implement IPsec encryption services, this is a finding.
V-239956
False
CASA-VN-000200
Verify the ASA uses a FIPS-validated cryptographic module to implement IPsec encryption services.
crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption aes-256
If the ASA is not configured to use a FIPS-validated cryptographic module to implement IPsec encryption services, this is a finding.
M
5344