STIGQter STIGQter: STIG Summary: Cisco ASA VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The Cisco ASA VPN remote access server must be configured to use an approved High Assurance Commercial Solution for Classified (CSfC) cryptographic algorithm for remote access to a classified network.

DISA Rule

SV-239985r878134_rule

Vulnerability Number

V-239985

Group Title

SRG-NET-000565-VPN-002390

Rule Version

CASA-VN-000760

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the ASA to use an approved High Assurance CSfC cryptographic algorithm for remote access to a classified network.

Step 1: Configure the IKE Phase 1.

ASA2(config)# crypto ikev2 policy 2
ASA2(config-ikev2-policy)# encryption aes-256
ASA2(config-ikev2-policy)# integrity null
ASA2(config-ikev2-policy)# group 20
ASA2(config-ikev2-policy)# prf sha384
ASA2(config-ikev2-policy)# exit

Step 2: Configure the IPsec proposal in compliance with CNSA/CNSSP-15 and apply to a crypto map as shown in the example below.

ASA2(config-ipsec-proposal)# protocol esp encryption aes-256
ASA2(config-ipsec-proposal)# exit
ASA2(config)# crypto map CSNA_MAP 10 set ikev2 ipsec-proposal AES-256
ASA2(config)# end

Check Contents

Verify the ASA uses an approved High Assurance CSfC cryptographic algorithm for remote access to a classified network.

Step 1: Verify IKE Phase 1 is configured in compliance with CSNA/CNSSP-15 parameters as shown in the example below.

crypto ikev2 policy 2
encryption aes-256
integrity null
group 19
prf sha384

Step 2: Determine the crypto map for IKE Phase 2 used is in compliance with CSNA/CNSSP-15 as in the example below.

crypto map CSNA_MAP 10 set ikev2 ipsec-proposal AES-256

Step 3: Verify the proposal specifies CSNA/CNSSP-15 parameters.

crypto ipsec ikev2 ipsec-proposal AES-256
protocol esp encryption aes-256

If the ASA is not configured to use an approved High Assurance CSfC cryptographic algorithm for remote access to a classified network, this is a finding.

Vulnerability Number

V-239985

Documentable

False

Rule Version

CASA-VN-000760

Severity Override Guidance

Verify the ASA uses an approved High Assurance CSfC cryptographic algorithm for remote access to a classified network.

Step 1: Verify IKE Phase 1 is configured in compliance with CSNA/CNSSP-15 parameters as shown in the example below.

crypto ikev2 policy 2
encryption aes-256
integrity null
group 19
prf sha384

Step 2: Determine the crypto map for IKE Phase 2 used is in compliance with CSNA/CNSSP-15 as in the example below.

crypto map CSNA_MAP 10 set ikev2 ipsec-proposal AES-256

Step 3: Verify the proposal specifies CSNA/CNSSP-15 parameters.

crypto ipsec ikev2 ipsec-proposal AES-256
protocol esp encryption aes-256

If the ASA is not configured to use an approved High Assurance CSfC cryptographic algorithm for remote access to a classified network, this is a finding.

Check Content Reference

M

Target Key

5344