STIGQter STIGQter: STIG Summary:

Ivanti Connect Secure VPN Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 01 Oct 2025

CheckedNameTitle
SV-258583r1117237_ruleThe ICS must be configured to ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies.
SV-258584r1056127_ruleThe ICS must display the Standard Mandatory DOD Notice and Consent Banner before granting access to users.
SV-258585r997504_ruleThe ICS must be configured to limit the number of concurrent sessions for user accounts to one.
SV-258586r997505_ruleThe ICS must be configured to use TLS 1.2, at a minimum.
SV-258587r930449_ruleThe ICS must be configured to generate log records containing sufficient information about where, when, identity, source, or outcome of the events.
SV-258588r930452_ruleThe ICS must be configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-258589r954210_ruleThe ICS must be configured to use multifactor authentication (e.g., DOD PKI) for network access to nonprivileged accounts.
SV-258590r930458_ruleThe ICS, when utilizing PKI-based authentication, must be configured to validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-258591r1136932_ruleThe ICS must terminate remote access network connections after 10 minutes or less.
SV-258592r930464_ruleThe ICS must be configured to send user traffic log data to redundant central log server.
SV-258593r930467_ruleThe ICS must be configured to forward all log failure events where the detection and/or prevention function is unable to write events to local log record or send an SNMP trap that can be forwarded to the SCA and ISSO.
SV-258594r930470_ruleThe ICS must be configured to authenticate all clients before establishing a connection.
SV-258595r1117244_ruleThe ICS must be configured to use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network.
SV-258596r1005432_ruleThe ICS must be configured to disable split-tunneling for remote client VPNs.
SV-258597r930479_ruleThe ICS that provides a Simple Network Management Protocol (SNMP) Network Management System (NMS) must configure SNMPv3 to use FIPS-validated AES cipher block algorithm.