SV-264334r984338_rule
V-264334
SRG-NET-000355
SRG-NET-000355-VPN-002433
CAT II
10
Configure the VPN Gateway to only allow the use of DOD PKI-established CAs for the establishment of VPN sessions. Configure validation for both the user and machine certificates.
If the VPN Gateway does not provide PKI-based user authentication intermediary services, this is not applicable.
Verify the VPN Gateway only allows the use of DOD PKI-established CA for verification when establishing VPN sessions.
Verify both user and machine certificates are being validated when establishing VPN sessions.
If the VPN Gateway does not validate user and machine certificates using DOD PKI-established certificate authorities, this is a finding.
V-264334
False
SRG-NET-000355-VPN-002433
If the VPN Gateway does not provide PKI-based user authentication intermediary services, this is not applicable.
Verify the VPN Gateway only allows the use of DOD PKI-established CA for verification when establishing VPN sessions.
Verify both user and machine certificates are being validated when establishing VPN sessions.
If the VPN Gateway does not validate user and machine certificates using DOD PKI-established certificate authorities, this is a finding.
M
2920