STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA remote access VPN server must be configured to use TLS 1.2 or higher to protect the confidentiality of remote access connections.

DISA Rule

SV-239975r666331_rule

Vulnerability Number

V-239975

Group Title

SRG-NET-000062-VPN-000200

Rule Version

CASA-VN-000550

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to use TLS 1.2 or higher as shown in the example below.

ASA1(config)# ssl server-version tlsv1.2 dtlsv1.2

Check Contents

Verify the TLS ASA is configured to use TLS 1.2 or higher as shown in the example below.

ssl server-version tlsv1.2 dtlsv1.2

Note: ASA supports TLS version 1.2 starting from software version 9.3.1 for secure message transmission for Clientless SSL VPN and AnyConnect VPN.

If the ASA is not configured to use TLS 1.2 or higher to protect the confidentiality of sensitive data during transmission, this is a finding.

Vulnerability Number

V-239975

Documentable

False

Rule Version

CASA-VN-000550

Severity Override Guidance

Verify the TLS ASA is configured to use TLS 1.2 or higher as shown in the example below.

ssl server-version tlsv1.2 dtlsv1.2

Note: ASA supports TLS version 1.2 starting from software version 9.3.1 for secure message transmission for Clientless SSL VPN and AnyConnect VPN.

If the ASA is not configured to use TLS 1.2 or higher to protect the confidentiality of sensitive data during transmission, this is a finding.

Check Content Reference

M

Target Key

5344