SV-266632r1040624_rule
V-266632
SRG-NET-000343
ARBA-NT-000850
CAT II
10
Configure AOS using the web interface:
1. Navigate to Configuration >> Services >> VPN and expand "Site-to-Site".
2. Select the configured site-to-site VPN IPsec maps. Select the applicable Server certificate. Select the applicable trusted DOD root CA under "CA certificate:".
3. Click Submit >> Pending Changes >> Deploy Changes.
4. Navigate to Configuration >> Access Points >> Remote APs tab.
5. Select the check box next to the AP Name in the Remote AP table and click "Provision".
6. In the "General" tab, select "Certificate" from the "Authentication method:" drop-down list.
7. Click "Submit" to apply the configuration and reboot the AP as a certificate Remote AP.
8. Click Pending Changes >> Deploy Changes.
If the AP is not being used as a Remote AP, this check is not applicable.
Verify the AOS configuration with the following commands:
1. Site-to-site VPN:
show crypto-local ipsec-map
If a CA certificate and Server certificate are not configured for each IPsec map, this is a finding.
2. Hardware client VPN:
show "remote ap profile"
If certificate authentication is not configured for each RAP profile, this is a finding.
V-266632
False
ARBA-NT-000850
If the AP is not being used as a Remote AP, this check is not applicable.
Verify the AOS configuration with the following commands:
1. Site-to-site VPN:
show crypto-local ipsec-map
If a CA certificate and Server certificate are not configured for each IPsec map, this is a finding.
2. Hardware client VPN:
show "remote ap profile"
If certificate authentication is not configured for each RAP profile, this is a finding.
M
5646