SV-239958r916134_rule
V-239958
SRG-NET-000168-VPN-000600
CASA-VN-000230
CAT II
10
Configure the ASA to use FIPS-validated SHA-2 at 384 bits or higher for IKE Phase 1 as shown in the example below.
ASA2(config)# crypto ikev2 policy 1
ASA2(config-ikev2-policy)# integrity sha384
Review the ASA configuration to verify that SHA-2 at 384 bits or higher is specified for IKE Phase 1 as shown in the example below.
crypto ikev2 policy 1
…
integrity sha384
If the ASA is not configured to use SHA-2 at 384 bits or higher for IKE Phase 1, this is a finding.
V-239958
False
CASA-VN-000230
Review the ASA configuration to verify that SHA-2 at 384 bits or higher is specified for IKE Phase 1 as shown in the example below.
crypto ikev2 policy 1
…
integrity sha384
If the ASA is not configured to use SHA-2 at 384 bits or higher for IKE Phase 1, this is a finding.
M
5344