STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA must be configured to use a FIPS-validated cryptographic module to implement IPsec encryption services.

DISA Rule

SV-239956r916128_rule

Vulnerability Number

V-239956

Group Title

SRG-NET-000510-VPN-002170

Rule Version

CASA-VN-000200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to use a FIPS-validated cryptographic module to implement IPsec encryption services as shown in the example below.

ASA2(config)# crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
ASA2(config-ipsec-proposal)# protocol esp encryption aes-256

Check Contents

Verify the ASA uses a FIPS-validated cryptographic module to implement IPsec encryption services.

crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption aes-256

If the ASA is not configured to use a FIPS-validated cryptographic module to implement IPsec encryption services, this is a finding.

Vulnerability Number

V-239956

Documentable

False

Rule Version

CASA-VN-000200

Severity Override Guidance

Verify the ASA uses a FIPS-validated cryptographic module to implement IPsec encryption services.

crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption aes-256

If the ASA is not configured to use a FIPS-validated cryptographic module to implement IPsec encryption services, this is a finding.

Check Content Reference

M

Target Key

5344