STIGQter STIGQter: STIG Summary:

HPE Aruba Networking AOS VPN Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 22 Oct 2024

CheckedNameTitle
SV-266982r1040712_ruleAOS, when used as an IPsec VPN Gateway, must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation.
SV-266983r1040715_ruleAOS, when used as a VPN Gateway, must be configured to use IPsec with SHA-2 at 384 bits or greater for hashing to protect the integrity of remote access sessions.
SV-266984r1040891_ruleAOS, when used as a VPN Gateway and using public key infrastructure (PKI)-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-266985r1040721_ruleAOS, when used as an IPsec VPN Gateway, must use Advanced Encryption Standard (AES) encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions.
SV-266986r1040894_ruleAOS, when used as a VPN Gateway, must use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network.
SV-266987r1040727_ruleAOS, when used as a VPN Gateway, must uniquely identify all network-connected endpoint devices before establishing a connection.
SV-266988r1040893_ruleAOS, when used as a VPN Gateway, must authenticate all network-connected endpoint devices before establishing a connection.
SV-266989r1040733_ruleThe Remote Access VPN Gateway and/or client must display the Standard Mandatory DOD Notice and Consent Banner before granting remote access to the network.
SV-266990r1040736_ruleAOS, when used as a VPN Gateway, must terminate all network connections associated with a communications session at the end of the session.
SV-266991r1040739_ruleFor site-to-site VPN implementations using AOS, the Layer 2 Tunneling Protocol (L2TP) must be blocked or denied at the security boundary with the private network so unencrypted L2TP packets cannot traverse into the private network of the enclave.
SV-266992r1040904_ruleAOS, when used as a VPN Gateway, must ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies.
SV-266993r1040745_ruleAOS, when used as a VPN Gateway, must limit the number of concurrent sessions for user accounts to one or to an organization-defined number.
SV-266994r1040748_ruleThe Remote Access VPN Gateway must use a separate authentication server (e.g., Lightweight Directory Access Protocol [LDAP], Remote Authentication Dial-In User Service [RADIUS], Terminal Access Controller Access-Control System+ [TACACS+] to perform user authentication.
SV-266995r1040751_ruleThe VPN Gateway must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-266996r1040892_ruleThe Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period.
SV-266997r1040757_ruleAOS, when used as a VPN Gateway, must renegotiate the security association after 24 hours or less or as defined by the organization.
SV-266998r1040760_ruleThe Remote Access VPN Gateway must be configured to prohibit Point-to-Point Tunneling Protocol (PPTP) and Layer 2 Forwarding (L2F).
SV-266999r1040763_ruleAOS, when used as a VPN Gateway, must be configured to route sessions to an intrusion detection and prevention system (IDPS) for inspection.
SV-267000r1040766_ruleAOS, when used as a VPN Gateway, must disable split-tunneling for remote client VPNs.
SV-267001r1040895_ruleAOS, when used as an IPsec VPN Gateway, must use Internet Key Exchange (IKE) for IPsec VPN security associations (SAs).
SV-268313r1040899_ruleAOS, when used as a VPN Gateway, must not accept certificates that have been revoked when using PKI for authentication.