STIGQter STIGQter: STIG Summary: Ivanti Connect Secure VPN Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 01 Oct 2025:

The ICS that provides a Simple Network Management Protocol (SNMP) Network Management System (NMS) must configure SNMPv3 to use FIPS-validated AES cipher block algorithm.

DISA Rule

SV-258597r930479_rule

Vulnerability Number

V-258597

Group Title

SRG-NET-000550-VPN-002360

Rule Version

IVCS-VN-000440

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Only the relevant portion of the SNMP configuration is highlighted here.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
1. Under "User 1", type in a valid username. Select "AuthPriv". The priv protocol must be set to at least CFB-AES-128.
2. Type in the priv password.

Check Contents

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.

Under "User 1", if a user configuration in AuthPriv is not using at least SHA and CFB-AES-128, this is a finding.

Vulnerability Number

V-258597

Documentable

False

Rule Version

IVCS-VN-000440

Severity Override Guidance

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.

Under "User 1", if a user configuration in AuthPriv is not using at least SHA and CFB-AES-128, this is a finding.

Check Content Reference

M

Target Key

5559