STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA must be configured to use FIPS-validated SHA-2 at 384 bits or higher for Internet Key Exchange (IKE) Phase 1.

DISA Rule

SV-239958r916134_rule

Vulnerability Number

V-239958

Group Title

SRG-NET-000168-VPN-000600

Rule Version

CASA-VN-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to use FIPS-validated SHA-2 at 384 bits or higher for IKE Phase 1 as shown in the example below.

ASA2(config)# crypto ikev2 policy 1
ASA2(config-ikev2-policy)# integrity sha384

Check Contents

Review the ASA configuration to verify that SHA-2 at 384 bits or higher is specified for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1

integrity sha384

If the ASA is not configured to use SHA-2 at 384 bits or higher for IKE Phase 1, this is a finding.

Vulnerability Number

V-239958

Documentable

False

Rule Version

CASA-VN-000230

Severity Override Guidance

Review the ASA configuration to verify that SHA-2 at 384 bits or higher is specified for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1

integrity sha384

If the ASA is not configured to use SHA-2 at 384 bits or higher for IKE Phase 1, this is a finding.

Check Content Reference

M

Target Key

5344