STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA remote access VPN server must be configured to use a FIPS-validated algorithm and hash function to protect the integrity of TLS remote access sessions.

DISA Rule

SV-239976r769253_rule

Vulnerability Number

V-239976

Group Title

SRG-NET-000063-VPN-000210

Rule Version

CASA-VN-000560

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the remote access ASA to use a digital signature generated using FIPS-validated algorithms and an approved hash.

ASA1(config)# ssl cipher tlsv1.2 fips
ASA1(config)# end

Check Contents

Verify the remote access ASA uses a FIPS-validated algorithms and hash function as shown in the example below.

ssl server-version tlsv1.2
ssl cipher tlsv1.2 fips

If the remote access ASA does not use a digital signature generated using FIPS-validated algorithms and hash function, this is a finding.

Vulnerability Number

V-239976

Documentable

False

Rule Version

CASA-VN-000560

Severity Override Guidance

Verify the remote access ASA uses a FIPS-validated algorithms and hash function as shown in the example below.

ssl server-version tlsv1.2
ssl cipher tlsv1.2 fips

If the remote access ASA does not use a digital signature generated using FIPS-validated algorithms and hash function, this is a finding.

Check Content Reference

M

Target Key

5344