SV-266278r1024913_rule
V-266278
SRG-NET-000317-VPN-001090
F5BI-VN-300005
CAT I
10
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Configure an AES256 encryption algorithm under IKE Phase 1 Algorithms >> Encryption Algorithm.
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify an AES256 encryption algorithm is selected under IKE Phase 1 Algorithms >> Encryption Algorithm.
If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IKE proposal, this is a finding.
V-266278
False
F5BI-VN-300005
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify an AES256 encryption algorithm is selected under IKE Phase 1 Algorithms >> Encryption Algorithm.
If the BIG-IP appliance is not configured to use AES256 or greater encryption for the IKE proposal, this is a finding.
M
5642