SV-266285r1024760_rule
V-266285
SRG-NET-000400-VPN-001940
F5BI-VN-300033
CAT I
10
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Configure the value for "Authentication Algorithm" under "IKE Phase 1 Algorithms" to "SHA-256" or higher.
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify that the value for "Authentication Algorithm" under "IKE Phase 1 Algorithms" is set to "SHA-256" or higher.
If the BIG-IP appliance is not configured to use SHA-2 or later protocol to protect the integrity of the password authentication process, this is a finding.
V-266285
False
F5BI-VN-300033
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the Name of the IKE peer.
5. Verify that the value for "Authentication Algorithm" under "IKE Phase 1 Algorithms" is set to "SHA-256" or higher.
If the BIG-IP appliance is not configured to use SHA-2 or later protocol to protect the integrity of the password authentication process, this is a finding.
M
5642