| Checked | Name | Title |
|---|
| ☐ | SV-266982r1040712_rule | AOS, when used as an IPsec VPN Gateway, must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation. |
| ☐ | SV-266983r1040715_rule | AOS, when used as a VPN Gateway, must be configured to use IPsec with SHA-2 at 384 bits or greater for hashing to protect the integrity of remote access sessions. |
| ☐ | SV-266984r1040891_rule | AOS, when used as a VPN Gateway and using public key infrastructure (PKI)-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-266985r1040721_rule | AOS, when used as an IPsec VPN Gateway, must use Advanced Encryption Standard (AES) encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions. |
| ☐ | SV-266986r1040894_rule | AOS, when used as a VPN Gateway, must use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network. |
| ☐ | SV-266987r1040727_rule | AOS, when used as a VPN Gateway, must uniquely identify all network-connected endpoint devices before establishing a connection. |
| ☐ | SV-266988r1040893_rule | AOS, when used as a VPN Gateway, must authenticate all network-connected endpoint devices before establishing a connection. |
| ☐ | SV-266989r1040733_rule | The Remote Access VPN Gateway and/or client must display the Standard Mandatory DOD Notice and Consent Banner before granting remote access to the network. |
| ☐ | SV-266990r1040736_rule | AOS, when used as a VPN Gateway, must terminate all network connections associated with a communications session at the end of the session. |
| ☐ | SV-266991r1040739_rule | For site-to-site VPN implementations using AOS, the Layer 2 Tunneling Protocol (L2TP) must be blocked or denied at the security boundary with the private network so unencrypted L2TP packets cannot traverse into the private network of the enclave. |
| ☐ | SV-266992r1040904_rule | AOS, when used as a VPN Gateway, must ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies. |
| ☐ | SV-266993r1040745_rule | AOS, when used as a VPN Gateway, must limit the number of concurrent sessions for user accounts to one or to an organization-defined number. |
| ☐ | SV-266994r1040748_rule | The Remote Access VPN Gateway must use a separate authentication server (e.g., Lightweight Directory Access Protocol [LDAP], Remote Authentication Dial-In User Service [RADIUS], Terminal Access Controller Access-Control System+ [TACACS+] to perform user authentication. |
| ☐ | SV-266995r1040751_rule | The VPN Gateway must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-266996r1040892_rule | The Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period. |
| ☐ | SV-266997r1040757_rule | AOS, when used as a VPN Gateway, must renegotiate the security association after 24 hours or less or as defined by the organization. |
| ☐ | SV-266998r1040760_rule | The Remote Access VPN Gateway must be configured to prohibit Point-to-Point Tunneling Protocol (PPTP) and Layer 2 Forwarding (L2F). |
| ☐ | SV-266999r1040763_rule | AOS, when used as a VPN Gateway, must be configured to route sessions to an intrusion detection and prevention system (IDPS) for inspection. |
| ☐ | SV-267000r1040766_rule | AOS, when used as a VPN Gateway, must disable split-tunneling for remote client VPNs. |
| ☐ | SV-267001r1040895_rule | AOS, when used as an IPsec VPN Gateway, must use Internet Key Exchange (IKE) for IPsec VPN security associations (SAs). |
| ☐ | SV-268313r1040899_rule | AOS, when used as a VPN Gateway, must not accept certificates that have been revoked when using PKI for authentication. |