STIGQter STIGQter: STIG Summary: Network WLAN Controller Platform Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 27 Apr 2023:

WLAN must use EAP-TLS.

DISA Rule

SV-243234r720157_rule

Vulnerability Number

V-243234

Group Title

SRG-NET-000070

Rule Version

WLAN-NW-000500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change the WLAN configuration so it supports EAP-TLS, implementing supporting PKI and AAA infrastructure as necessary. If the WLAN equipment is not capable of supporting EAP-TLS, procure new equipment capable of such support.

Check Contents

Note: If the equipment is WPA2/WPA3 certified by the Wi-Fi Alliance, it is capable of supporting this requirement.

Review the WLAN equipment configuration to verify that EAP-TLS is actively used and no other methods are enabled.

If EAP-TLS is not used or if the WLAN system allows users to connect with other methods, this is a finding.

Vulnerability Number

V-243234

Documentable

False

Rule Version

WLAN-NW-000500

Severity Override Guidance

Note: If the equipment is WPA2/WPA3 certified by the Wi-Fi Alliance, it is capable of supporting this requirement.

Review the WLAN equipment configuration to verify that EAP-TLS is actively used and no other methods are enabled.

If EAP-TLS is not used or if the WLAN system allows users to connect with other methods, this is a finding.

Check Content Reference

M

Target Key

5398