SV-266288r1024921_rule
V-266288
SRG-NET-000371-VPN-001640
F5BI-VN-300044
CAT II
10
From the BIG-IP GUI:
1. Network
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Select any value other than "NONE" in "IKE Phase 2 >> Perfect Forward Secrecy".
6. Click "Update".
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify "NONE" is not selected in "IKE Phase 2 >> Perfect Forward Secrecy".
If the BIG-IP appliance is not configured to specify PFS during IKE negotiation, this is a finding.
V-266288
False
F5BI-VN-300044
From the BIG-IP GUI:
1. Network.
2. IPsec.
3. IPsec Policies.
4. Click on the name of the IPsec Policy.
5. Verify "NONE" is not selected in "IKE Phase 2 >> Perfect Forward Secrecy".
If the BIG-IP appliance is not configured to specify PFS during IKE negotiation, this is a finding.
M
5642