SV-239968r954210_rule
V-239968
SRG-NET-000140-VPN-000500
CASA-VN-000440
CAT I
10
Configure the ASA to enforce certificate-based authentication before granting access to the network as shown in the example below.
ASA1(config)# tunnel-group ANY_CONNECT webvpn-attributes
ASA1(config-tunnel-webvpn)# authentication certificate
ASA1(config-tunnel-webvpn)# end
Review the ASA configuration to verify that it enforces certificate-based authentication before granting access to the network as shown in the example below.
tunnel-group ANY_CONNECT type remote-access
tunnel-group ANY_CONNECT webvpn-attributes
authentication certificate
If the ASA configuration does not enforce certificate-based authentication before granting access to the network, this is a finding.
V-239968
False
CASA-VN-000440
Review the ASA configuration to verify that it enforces certificate-based authentication before granting access to the network as shown in the example below.
tunnel-group ANY_CONNECT type remote-access
tunnel-group ANY_CONNECT webvpn-attributes
authentication certificate
If the ASA configuration does not enforce certificate-based authentication before granting access to the network, this is a finding.
M
5344