STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as a VPN Gateway, must be configured to use IPsec with SHA-2 at 384 bits or greater for hashing to protect the integrity of remote access sessions.

DISA Rule

SV-266983r1040715_rule

Vulnerability Number

V-266983

Group Title

SRG-NET-000063-VPN-000220

Rule Version

ARBA-VN-000220

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
crypto isakmp policy <priority>
hash sha2-384-192
exit
write memory

Check Contents

1. Verify the AOS configuration with the following command:
show crypto-local ipsec-map

Note the IKEv2 Policy number for each configured map.

2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>

If each configured IKEv2 policy hash algorithm is not configured with SHA-2 at 384 bit, this is a finding.

Vulnerability Number

V-266983

Documentable

False

Rule Version

ARBA-VN-000220

Severity Override Guidance

1. Verify the AOS configuration with the following command:
show crypto-local ipsec-map

Note the IKEv2 Policy number for each configured map.

2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>

If each configured IKEv2 policy hash algorithm is not configured with SHA-2 at 384 bit, this is a finding.

Check Content Reference

M

Target Key

5645