SV-266287r1024762_rule
V-266287
SRG-NET-000230-VPN-000780
F5BI-VN-300041
CAT I
10
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Configure SHA-2 or higher for the following:
IKE Phase 1 Algorithms >> Authentication Algorithm
IKE Phase 1 Algorithms >> Pseudo-Random Function
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click the name of the IPsec Policy.
5. Configure SHA-2 or higher for the following:
IKE Phase 2 >> Authentication Algorithm
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify "SHA-1" or "MD5" is not selected for the following:
IKE Phase 1 Algorithms >> Authentication Algorithm
IKE Phase 1 Algorithms >> Pseudo-Random Function
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click the name of the IPsec Policy.
5. Verify "SHA-1" is not selected for the following:
IKE Phase 2 >> Authentication Algorithm
If the BIG-IP appliance is not configured to use FIPS-validated SHA-2 or higher for IKE, this is a finding.
V-266287
False
F5BI-VN-300041
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IKE Peers.
4. Click on the name of the IKE peer.
5. Verify "SHA-1" or "MD5" is not selected for the following:
IKE Phase 1 Algorithms >> Authentication Algorithm
IKE Phase 1 Algorithms >> Pseudo-Random Function
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click the name of the IPsec Policy.
5. Verify "SHA-1" is not selected for the following:
IKE Phase 2 >> Authentication Algorithm
If the BIG-IP appliance is not configured to use FIPS-validated SHA-2 or higher for IKE, this is a finding.
M
5642