STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS VPN Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS, when used as an IPsec VPN Gateway, must use Internet Key Exchange (IKE) for IPsec VPN security associations (SAs).

DISA Rule

SV-267001r1040895_rule

Vulnerability Number

V-267001

Group Title

SRG-NET-000512-VPN-002220

Rule Version

ARBA-VN-002220

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS with the following commands:
configure terminal
crypto-local ipsec-map <name> <priority>
version v2
exit
write memory

Check Contents

Verify the AOS configuration with the following command:
show crypto-local ipsec-map

If each configured IPsec map is not configured with IKE, this is a finding.

Vulnerability Number

V-267001

Documentable

False

Rule Version

ARBA-VN-002220

Severity Override Guidance

Verify the AOS configuration with the following command:
show crypto-local ipsec-map

If each configured IPsec map is not configured with IKE, this is a finding.

Check Content Reference

M

Target Key

5645