STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The TLS VPN must be configured to limit authenticated client sessions to initial session source IP.

DISA Rule

SV-264335r1138025_rule

Vulnerability Number

V-264335

Group Title

SRG-NET-000019

Rule Version

SRG-NET-000019-VPN-002435

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the TLS VPN Gateway to limit authenticated client sessions to initial session source IP.

Check Contents

Verify the TLS VPN Gateway limits authenticated client sessions to initial session source IP.

If the TLS VPN Gateway does not limit authenticated client sessions to initial session source IP, this is a finding.

Vulnerability Number

V-264335

Documentable

False

Rule Version

SRG-NET-000019-VPN-002435

Severity Override Guidance

Verify the TLS VPN Gateway limits authenticated client sessions to initial session source IP.

If the TLS VPN Gateway does not limit authenticated client sessions to initial session source IP, this is a finding.

Check Content Reference

M

Target Key

2920