STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco VPN remote access server must be configured to accept Common Access Card (CAC) credential credentials.

DISA Rule

SV-239981r856175_rule

Vulnerability Number

V-239981

Group Title

SRG-NET-000341-VPN-001350

Rule Version

CASA-VN-000660

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to accept CAC credentials as shown in the example below.

ASA1(config)# tunnel-group ANY_CONNECT webvpn-attributes
ASA1(config-tunnel-webvpn)# authentication certificate
ASA1(config-tunnel-webvpn)# end

Check Contents

Verify the ASA accepts CAC credentials as shown in the example below.

tunnel-group ANY_CONNECT type remote-access
tunnel-group ANY_CONNECT webvpn-attributes
authentication certificate

If the ASA does not accept PIV credentials, this is a finding.

Vulnerability Number

V-239981

Documentable

False

Rule Version

CASA-VN-000660

Severity Override Guidance

Verify the ASA accepts CAC credentials as shown in the example below.

tunnel-group ANY_CONNECT type remote-access
tunnel-group ANY_CONNECT webvpn-attributes
authentication certificate

If the ASA does not accept PIV credentials, this is a finding.

Check Content Reference

M

Target Key

5344