STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA VPN gateway must be configured to restrict what traffic is transported via the IPsec tunnel according to flow control policies.

DISA Rule

SV-239960r666286_rule

Vulnerability Number

V-239960

Group Title

SRG-NET-000019-VPN-000040

Rule Version

CASA-VN-000300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Step 1: Define what traffic will be transported via the IPsec tunnel as shown in the example below.

ASA1(config)# access-list SITE1_SITE2 extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0

Step 2: Apply the ACL to the IPsec crypto map.

ASA1(config)# crypto map IPSEC_MAP 10 match address SITE1_SITE2

Check Contents

Step 1: Determine the ACL that is used to define what traffic will be transported via the IPsec tunnel.

crypto map IPSEC_MAP 10 match address SITE1_SITE2
crypto map IPSEC_MAP 10 set peer x.x.x.x

Step 2: Verify that the traffic defined in the ACL is in accordance with flow control policies.

access-list SITE1_SITE2 extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0

If the VPN gateway is not configured to restrict what traffic is transported via the IPsec tunnel, this is a finding.

Vulnerability Number

V-239960

Documentable

False

Rule Version

CASA-VN-000300

Severity Override Guidance

Step 1: Determine the ACL that is used to define what traffic will be transported via the IPsec tunnel.

crypto map IPSEC_MAP 10 match address SITE1_SITE2
crypto map IPSEC_MAP 10 set peer x.x.x.x

Step 2: Verify that the traffic defined in the ACL is in accordance with flow control policies.

access-list SITE1_SITE2 extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0

If the VPN gateway is not configured to restrict what traffic is transported via the IPsec tunnel, this is a finding.

Check Content Reference

M

Target Key

5344