STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA VPN gateway must be configured to renegotiate the IKE security association after 24 hours or less.

DISA Rule

SV-239964r1015264_rule

Vulnerability Number

V-239964

Group Title

SRG-NET-000337-VPN-001300

Rule Version

CASA-VN-000360

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN gateway to renegotiate the IKE security association after 24 hours or less as shown in the example below.

ASA2(config)# crypto ikev2 policy 2
ASA2(config-ikev2-policy)# lifetime seconds 86400
ASA2(config-ikev2-policy)# end

Check Contents

Verify the VPN gateway renegotiates the IKE security association after 24 hours or less as shown in the example below.

crypto ikev2 policy 2
encryption …



lifetime seconds 86400

If the VPN gateway does not renegotiate the IKE security association after 24 hours or less, this is a finding.

Vulnerability Number

V-239964

Documentable

False

Rule Version

CASA-VN-000360

Severity Override Guidance

Verify the VPN gateway renegotiates the IKE security association after 24 hours or less as shown in the example below.

crypto ikev2 policy 2
encryption …



lifetime seconds 86400

If the VPN gateway does not renegotiate the IKE security association after 24 hours or less, this is a finding.

Check Content Reference

M

Target Key

5344