STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Gateway providing authentication intermediary services must only accept end entity certificates (user or machine) issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of VPN sessions.

DISA Rule

SV-264334r984338_rule

Vulnerability Number

V-264334

Group Title

SRG-NET-000355

Rule Version

SRG-NET-000355-VPN-002433

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Gateway to only allow the use of DOD PKI-established CAs for the establishment of VPN sessions. Configure validation for both the user and machine certificates.

Check Contents

If the VPN Gateway does not provide PKI-based user authentication intermediary services, this is not applicable.

Verify the VPN Gateway only allows the use of DOD PKI-established CA for verification when establishing VPN sessions.

Verify both user and machine certificates are being validated when establishing VPN sessions.

If the VPN Gateway does not validate user and machine certificates using DOD PKI-established certificate authorities, this is a finding.

Vulnerability Number

V-264334

Documentable

False

Rule Version

SRG-NET-000355-VPN-002433

Severity Override Guidance

If the VPN Gateway does not provide PKI-based user authentication intermediary services, this is not applicable.

Verify the VPN Gateway only allows the use of DOD PKI-established CA for verification when establishing VPN sessions.

Verify both user and machine certificates are being validated when establishing VPN sessions.

If the VPN Gateway does not validate user and machine certificates using DOD PKI-established certificate authorities, this is a finding.

Check Content Reference

M

Target Key

2920