STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA VPN remote access server must be configured to disable split-tunneling for remote clients.

DISA Rule

SV-239982r1005432_rule

Vulnerability Number

V-239982

Group Title

SRG-NET-000369-VPN-001620

Rule Version

CASA-VN-000700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to disable split-tunneling for remote clients VPNs as shown in the example below.

ASA2(config)# group-policy ANY_CONNECT_GROUP attributes
ASA2(config-group-policy)# split-tunnel-policy tunnelall
ASA2(config-group-policy)# end

Check Contents

Verify the ASA disables split-tunneling for remote clients VPNs as shown in the example below.

group-policy ANY_CONNECT_GROUP attributes



split-tunnel-policy tunnelall

If the ASA does not disable split-tunneling for remote clients VPNs, this is a finding.

Note: Certain cloud products require direct connectivity to operate correctly. These items may be excluded from the split tunneling restriction if documented and approved.

If split-tunneling for remote client VPNs is enabled by the above exception, verify only authorized external destinations are excluded from tunneling as shown in the example below:

Webvpn
anyconnect-custom-attr dynamic-split-exclude-domains description DoD IL5 Authorized Destinations
anyconnect-custom-data dynamic-split-exclude-domains DoD-IL5 dod.teams.microsoft.us,azureedge.net,core.usgovcloudapi.net,streaming.media.usgovcloudapi.net,wvd.azure.us,cdn.office365.us

anyconnect-custom dynamic-split-exclude-domains value DoD-IL5

If any unauthorized exempted connections exist, this is a finding.

Vulnerability Number

V-239982

Documentable

False

Rule Version

CASA-VN-000700

Severity Override Guidance

Verify the ASA disables split-tunneling for remote clients VPNs as shown in the example below.

group-policy ANY_CONNECT_GROUP attributes



split-tunnel-policy tunnelall

If the ASA does not disable split-tunneling for remote clients VPNs, this is a finding.

Note: Certain cloud products require direct connectivity to operate correctly. These items may be excluded from the split tunneling restriction if documented and approved.

If split-tunneling for remote client VPNs is enabled by the above exception, verify only authorized external destinations are excluded from tunneling as shown in the example below:

Webvpn
anyconnect-custom-attr dynamic-split-exclude-domains description DoD IL5 Authorized Destinations
anyconnect-custom-data dynamic-split-exclude-domains DoD-IL5 dod.teams.microsoft.us,azureedge.net,core.usgovcloudapi.net,streaming.media.usgovcloudapi.net,wvd.azure.us,cdn.office365.us

anyconnect-custom dynamic-split-exclude-domains value DoD-IL5

If any unauthorized exempted connections exist, this is a finding.

Check Content Reference

M

Target Key

5344