STIGQter STIGQter: STIG Summary: Ivanti Connect Secure VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Oct 2025:

The ICS must terminate remote access network connections after 10 minutes or less.

DISA Rule

SV-258591r1136932_rule

Vulnerability Number

V-258591

Group Title

SRG-NET-000213-VPN-000721

Rule Version

IVCS-VN-000260

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the user role being used for CAC/PKI token VPN client logins with a session timeout.

In the ICS Web UI, navigate to Administrators >> Users Roles >> User Roles.
1. Click the configured user role being used for CAC/PKI token VPN client logins.
2. Click the "Session Options" tab.
3. In the "Session Lifetime" section, set the Idle Timeout to "10".
4. Click "Save Changes".

Check Contents

Verify the user role being used for CAC/PKI token VPN client logins is configured with a session timeout.

In the ICS Web UI, navigate to Administrators >> Users Roles >> User Roles.
1. Click the configured user role being used for CAC/PKI token VPN client logins.
2. Click the "Session Options" tab.

In the "Session Lifetime" section, if Idle Timeout is not set to "10", this is a finding.

Vulnerability Number

V-258591

Documentable

False

Rule Version

IVCS-VN-000260

Severity Override Guidance

Verify the user role being used for CAC/PKI token VPN client logins is configured with a session timeout.

In the ICS Web UI, navigate to Administrators >> Users Roles >> User Roles.
1. Click the configured user role being used for CAC/PKI token VPN client logins.
2. Click the "Session Options" tab.

In the "Session Lifetime" section, if Idle Timeout is not set to "10", this is a finding.

Check Content Reference

M

Target Key

5559