SV-266286r1024761_rule
V-266286
SRG-NET-000565-VPN-002400
F5BI-VN-300040
CAT I
10
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Configure "IKE Phase 1 Algorithms" to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Configure "IKE Phase 2" to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify that "IKE Phase 1 Algorithms" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify that "IKE Phase 2" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network, this is a finding.
V-266286
False
F5BI-VN-300040
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify that "IKE Phase 1 Algorithms" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify that "IKE Phase 2" use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
If the BIG-IP appliance is not configured to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network, this is a finding.
M
5642