SV-266985r1040721_rule
V-266985
SRG-NET-000317-VPN-001090
ARBA-VN-001090
CAT I
10
Configure AOS with the following commands for each IKEv2 Policy number noted:
configure terminal
crypto isakmp policy <priority>
encryption aes256
exit
write memory
1. Verify the AOS configuration with the following commands:
show crypto-local ipsec-map
Note the IKEv2 Policy number for each configured map.
2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>
If each configured IKEv2 policy is not configured with AES256 or greater encryption, this is a finding.
V-266985
False
ARBA-VN-001090
1. Verify the AOS configuration with the following commands:
show crypto-local ipsec-map
Note the IKEv2 Policy number for each configured map.
2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>
If each configured IKEv2 policy is not configured with AES256 or greater encryption, this is a finding.
M
5645