STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as an IPsec VPN Gateway, must use Advanced Encryption Standard (AES) encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions.

DISA Rule

SV-266985r1040721_rule

Vulnerability Number

V-266985

Group Title

SRG-NET-000317-VPN-001090

Rule Version

ARBA-VN-001090

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands for each IKEv2 Policy number noted:
configure terminal
crypto isakmp policy <priority>
encryption aes256
exit
write memory

Check Contents

1. Verify the AOS configuration with the following commands:
show crypto-local ipsec-map

Note the IKEv2 Policy number for each configured map.

2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>

If each configured IKEv2 policy is not configured with AES256 or greater encryption, this is a finding.

Vulnerability Number

V-266985

Documentable

False

Rule Version

ARBA-VN-001090

Severity Override Guidance

1. Verify the AOS configuration with the following commands:
show crypto-local ipsec-map

Note the IKEv2 Policy number for each configured map.

2. For each configured policy number, run the following command:
show crypto isakmp policy <IKEv2 Policy #>

If each configured IKEv2 policy is not configured with AES256 or greater encryption, this is a finding.

Check Content Reference

M

Target Key

5645