SV-266983r1040715_rule
V-266983
SRG-NET-000063-VPN-000220
ARBA-VN-000220
CAT II
10
Configure AOS with the following commands:
configure terminal
crypto isakmp policy <priority>
hash sha2-384-192
exit
write memory
1. Verify the AOS configuration with the following command:
show crypto-local ipsec-map
Note the IKEv2 Policy number for each configured map.
2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>
If each configured IKEv2 policy hash algorithm is not configured with SHA-2 at 384 bit, this is a finding.
V-266983
False
ARBA-VN-000220
1. Verify the AOS configuration with the following command:
show crypto-local ipsec-map
Note the IKEv2 Policy number for each configured map.
2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>
If each configured IKEv2 policy hash algorithm is not configured with SHA-2 at 384 bit, this is a finding.
M
5645