STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as an IPsec VPN Gateway, must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation.

DISA Rule

SV-266982r1040712_rule

Vulnerability Number

V-266982

Group Title

SRG-NET-000371-VPN-001640

Rule Version

ARBA-VN-001640

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
crypto-local ipsec-map <map name> <priority #>
set pfs group 19
exit
write memory

Check Contents

Verify the AOS configuration with the following command:
show crypto-local ipsec-map

If each active IPsec map does not show PFS enabled, this is a finding.

Vulnerability Number

V-266982

Documentable

False

Rule Version

ARBA-VN-001640

Severity Override Guidance

Verify the AOS configuration with the following command:
show crypto-local ipsec-map

If each active IPsec map does not show PFS enabled, this is a finding.

Check Content Reference

M

Target Key

5645