STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1.

DISA Rule

SV-239957r916149_rule

Vulnerability Number

V-239957

Group Title

SRG-NET-000074-VPN-000250

Rule Version

CASA-VN-000210

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to use a DH Group of 16 or greater as shown in the example below.

ASA1(config)# crypto ikev2 policy 1
ASA1(config-ikev2-policy)# group 24

Check Contents

Review the ASA configuration to determine if DH Group of 16 or greater has been specified for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1
encryption aes-256

group 24

If DH Group of 16 or greater has not been specified for IKE Phase 1, this is a finding.

Vulnerability Number

V-239957

Documentable

False

Rule Version

CASA-VN-000210

Severity Override Guidance

Review the ASA configuration to determine if DH Group of 16 or greater has been specified for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1
encryption aes-256

group 24

If DH Group of 16 or greater has not been specified for IKE Phase 1, this is a finding.

Check Content Reference

M

Target Key

5344