SV-267000r1040766_rule
V-267000
SRG-NET-000369-VPN-001620
ARBA-VN-001620
CAT II
10
Configure AOS using the following commands:
configure terminal
wlan virtual-ap <profile name>
forward-mode tunnel
exit
write memory
ap system-profile <profile name>
double-encrypt
exit
write memory
For each VIA connection profile:
vaaa authentication via connection-profile <name>
no split-tunneling
exit
write memory
Verify the AOS configuration with the following commands:
show wlan virtual-ap
For each active WLAN virtual-ap profile:
show wlan virtual-ap <name> | include "Forward mode"
show ap system-profile
For each active AP system-profile:
show ap system-profile <name> | include "Double Encrypt"
show aaa authentication via connection-profile
For each referenced profile:
show aaa authentication via connection-profile <name> | include "Enable split tunneling"
If any instances of remote access or virtual-ap profile forward mode of split-tunnel are found or if double-encrypt is not enabled per active AP system profile, this is a finding.
V-267000
False
ARBA-VN-001620
Verify the AOS configuration with the following commands:
show wlan virtual-ap
For each active WLAN virtual-ap profile:
show wlan virtual-ap <name> | include "Forward mode"
show ap system-profile
For each active AP system-profile:
show ap system-profile <name> | include "Double Encrypt"
show aaa authentication via connection-profile
For each referenced profile:
show aaa authentication via connection-profile <name> | include "Enable split tunneling"
If any instances of remote access or virtual-ap profile forward mode of split-tunnel are found or if double-encrypt is not enabled per active AP system profile, this is a finding.
M
5645