SV-239979r987747_rule
V-239979
SRG-NET-000317-VPN-001090
CASA-VN-000640
CAT I
10
Configure the ASA to use AES256 or greater encryption algorithm for IKE Phase 1 as shown in the example below.
ASA1(config)# crypto ikev2 policy 1
ASA1(config-ikev2-policy)# encryption aes-256
Verify IKE Phase 1 is set to use an AES256 or greater encryption algorithm as shown in the example below.
crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption aes-256
If the value of the encryption algorithm for IKE Phase 1 is not set to use an AES256 or greater algorithm, this is a finding.
V-239979
False
CASA-VN-000640
Verify IKE Phase 1 is set to use an AES256 or greater encryption algorithm as shown in the example below.
crypto ipsec ikev2 ipsec-proposal IPSEC_TRANS
protocol esp encryption aes-256
If the value of the encryption algorithm for IKE Phase 1 is not set to use an AES256 or greater algorithm, this is a finding.
M
5344