STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA remote access VPN server must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the network.

DISA Rule

SV-239970r666316_rule

Vulnerability Number

V-239970

Group Title

SRG-NET-000041-VPN-000110

Rule Version

CASA-VN-000460

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the network as shown in the example below.

ASA3(config)# group-policy GROUP_POLICY_ANYCONNECT attributes
ASA3(config-group-policy)# banner value I've read & consent to terms in IS user agreem't.
ASA3(config-group-policy)# end

Check Contents

Verify that the ASA is configured to display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the network as shown in the example below.

group-policy GROUP_POLICY_ANYCONNECT attributes
banner value I've read & consent to terms in IS user agreem't.

If the ASA is not configured to display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the network, this is a finding.

Vulnerability Number

V-239970

Documentable

False

Rule Version

CASA-VN-000460

Severity Override Guidance

Verify that the ASA is configured to display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the network as shown in the example below.

group-policy GROUP_POLICY_ANYCONNECT attributes
banner value I've read & consent to terms in IS user agreem't.

If the ASA is not configured to display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the network, this is a finding.

Check Content Reference

M

Target Key

5344