| Checked | Name | Title |
|---|
| ☐ | SV-207184r1138024_rule | The VPN Gateway must ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies. |
| ☐ | SV-207185r1173942_rule | The Remote Access VPN Gateway and/or client must display the Standard Mandatory DOD Notice and Consent Banner before granting remote access to the network. |
| ☐ | SV-207186r1173943_rule | The Remote Access VPN Gateway and/or client must enforce a policy to retain the Standard Mandatory DOD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access. |
| ☐ | SV-207189r608988_rule | The VPN Gateway must limit the number of concurrent sessions for user accounts to 1 or to an organization-defined number. |
| ☐ | SV-207190r803417_rule | The TLS VPN Gateway must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during transmission for remote access connections. |
| ☐ | SV-207191r803418_rule | The remote access VPN Gateway must use a digital signature generated using FIPS-validated algorithms and an approved hash function to protect the integrity of TLS remote access sessions. |
| ☐ | SV-207192r916146_rule | The VPN Gateway must be configured to use IPsec with SHA-2 at 384 bits or greater for hashing to protect the integrity of remote access sessions. |
| ☐ | SV-207193r916149_rule | The IPSec VPN must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1. |
| ☐ | SV-207194r608988_rule | If the site-to-site VPN implementation uses L2TP, L2TPv3 sessions must be authenticated prior to transporting traffic. |
| ☐ | SV-207195r608988_rule | The VPN Gateway must generate log records containing information to establish what type of events occurred. |
| ☐ | SV-207196r608988_rule | The VPN Gateway must generate log records containing information to establish when (date and time) the events occurred. |
| ☐ | SV-207197r608988_rule | The VPN Gateway must generate log records containing information that establishes the identity of any individual or process associated with the event. |
| ☐ | SV-207198r608988_rule | The VPN Gateway must generate log records containing information to establish where the events occurred. |
| ☐ | SV-207199r1038960_rule | The VPN Gateway must generate log records containing information to establish the source of the events. |
| ☐ | SV-207200r608988_rule | The VPN Gateway must produce log records containing information to establish the outcome of the events. |
| ☐ | SV-207201r608988_rule | The VPN Gateway must protect log information from unauthorized read access if all or some of this data is stored locally. |
| ☐ | SV-207202r608988_rule | The VPN Gateway log must protect audit information from unauthorized modification when stored locally. |
| ☐ | SV-207203r608988_rule | The VPN Gateway must protect audit information from unauthorized deletion when stored locally. |
| ☐ | SV-207204r608988_rule | The VPN Gateway must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-207205r608988_rule | The IPsec VPN Gateway must use IKEv2 for IPsec VPN security associations. |
| ☐ | SV-207206r608988_rule | The Remote Access VPN Gateway must be configured to prohibit Point-to-Point Tunneling Protocol (PPTP) and L2F. |
| ☐ | SV-207207r608988_rule | For site-to-site VPN implementations, the L2TP protocol must be blocked or denied at the security boundary with the private network so unencrypted L2TP packets cannot traverse into the private network of the enclave. |
| ☐ | SV-207208r608988_rule | The VPN Gateway must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-207209r954210_rule | The VPN Gateway must use multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts. |
| ☐ | SV-207210r984299_rule | The VPN Client must implement multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access. |
| ☐ | SV-207211r984302_rule | The TLS VPN must be configured to use replay-resistant authentication mechanisms for network access to nonprivileged accounts. |
| ☐ | SV-207212r984303_rule | The IPsec VPN Gateway must use anti-replay mechanisms for security associations. |
| ☐ | SV-207213r608988_rule | The VPN Gateway must uniquely identify all network-connected endpoint devices before establishing a connection. |
| ☐ | SV-207214r608988_rule | The VPN Gateway, when utilizing PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-207215r608988_rule | The site-to-site VPN, when using PKI-based authentication for devices, must enforce authorized access to the corresponding private key. |
| ☐ | SV-207216r608988_rule | The Remote Access VPN Gateway must use a separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication. |
| ☐ | SV-207217r608988_rule | The VPN Gateway must map the authenticated identity to the user account for PKI-based authentication. |
| ☐ | SV-207218r803427_rule | The VPN Gateway must use FIPS-validated SHA-2 or higher hash function to protect the integrity of hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, hash-only applications, and digital signature verification. |
| ☐ | SV-207219r608988_rule | The VPN Gateway must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users). |
| ☐ | SV-207220r608988_rule | The VPN Gateway must be configured to route sessions to an IDPS for inspection. |
| ☐ | SV-207221r971530_rule | The VPN Gateway must terminate all network connections associated with a communications session at the end of the session. |
| ☐ | SV-207222r608988_rule | The VPN Gateway must use FIPS 140-2 compliant mechanisms for authentication to a cryptographic module. |
| ☐ | SV-207223r916152_rule | The IPSec VPN must be configured to use FIPS-validated SHA-2 at 384 bits or higher for Internet Key Exchange (IKE). |
| ☐ | SV-207224r608988_rule | The VPN Gateway must invalidate session identifiers upon user logoff or other session termination. |
| ☐ | SV-207225r608988_rule | The VPN Gateway must recognize only system-generated session identifiers. |
| ☐ | SV-207226r803431_rule | The VPN Gateway must generate unique session identifiers using FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm. |
| ☐ | SV-207227r608988_rule | The VPN Gateway must fail to a secure state if system initialization fails, shutdown fails, or aborts fail. |
| ☐ | SV-207228r856701_rule | The VPN Gateway must be configured to perform an organization-defined action if the audit reveals unauthorized activity. |
| ☐ | SV-207229r856702_rule | The VPN Gateway administrator accounts or security policy must be configured to allow the system administrator to immediately disconnect or disable remote access to devices and/or users when needed. |
| ☐ | SV-207230r987747_rule | The IPsec VPN Gateway must use AES encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions. |
| ☐ | SV-207234r856706_rule | The VPN Gateway must off-load audit records onto a different system or media than the system being audited. |
| ☐ | SV-207235r878129_rule | The VPN Gateway must generate a log record or an SNMP trap that can be forwarded as an alert to, at a minimum, the SCA and ISSO, of all log failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server. |
| ☐ | SV-207237r987783_rule | The VPN Gateway must renegotiate the IPsec security association (SA) after eight hours or less. |
| ☐ | SV-207238r987783_rule | The VPN Gateway must renegotiate the IKE security association (SA) after eight hours or less. |
| ☐ | SV-207239r856712_rule | The VPN Gateway must accept the Common Access Card (CAC) credential. |
| ☐ | SV-207240r856714_rule | The VPN Gateway must electronically verify the Common Access Card (CAC) credential. |
| ☐ | SV-207241r856715_rule | The VPN Gateway must authenticate all network-connected endpoint devices before establishing a connection. |
| ☐ | SV-207242r1138028_rule | The VPN Gateway must use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network. |
| ☐ | SV-207243r1005432_rule | The VPN Gateway must disable split-tunneling for remote clients VPNs. |
| ☐ | SV-207244r916233_rule | The IPsec VPN Gateway must specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation. |
| ☐ | SV-207245r856719_rule | The VPN Gateway and Client must be configured to protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-207247r1207726_rule | For accounts using password authentication, the site-to-site VPN Gateway must use SHA-2 or later protocol to protect the integrity of the password authentication process. |
| ☐ | SV-207248r608988_rule | The VPN Gateway must generate log records when successful and/or unsuccessful VPN connection attempts occur. |
| ☐ | SV-207249r1138029_rule | The VPN Gateway must use a FIPS-validated cryptographic module to generate cryptographic hashes. |
| ☐ | SV-207250r1138030_rule | The VPN Gateway must use a FIPS-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality. |
| ☐ | SV-207251r1138031_rule | The IPsec VPN Gateway IKE must use NIST FIPS-validated cryptography to implement encryption services for unclassified VPN traffic. |
| ☐ | SV-207252r608988_rule | The IPsec VPN Gateway must use Internet Key Exchange (IKE) for IPsec VPN Security Associations (SAs). |
| ☐ | SV-207254r856725_rule | The VPN Client logout function must be configured to terminate the session on/with the VPN Gateway. |
| ☐ | SV-207255r856726_rule | The VPN Client must display an explicit logout message to users indicating the reliable termination of authenticated communications sessions. |
| ☐ | SV-207256r984307_rule | For site-to-site, VPN Gateway must be configured to store only cryptographic representations of pre-shared Keys (PSKs). |
| ☐ | SV-207257r916158_rule | The IPsec VPN must use AES256 or greater encryption for the IPsec proposal to protect the confidentiality of remote access sessions. |
| ☐ | SV-207258r608988_rule | The TLS VPN Gateway that supports Government-only services must prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0. |
| ☐ | SV-207259r608988_rule | The TLS VPN Gateway that supports citizen- or business-facing network devices must prohibit client negotiation to SSL 2.0 or SSL 3.0. |
| ☐ | SV-207260r878130_rule | The VPN Gateway that provides a Simple Network Management Protocol (SNMP) Network Management System (NMS) must configure SNMPv3 to use FIPS-validated AES cipher block algorithm. |
| ☐ | SV-207261r1138034_rule | The VPN remote access server must be configured use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network. |
| ☐ | SV-207262r1138037_rule | The VPN gateway must use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network. |
| ☐ | SV-207263r608988_rule | The VPN Gateway must validate certificates used for Transport Layer Security (TLS) functions by performing RFC 5280-compliant certification path validation. |
| ☐ | SV-251044r971530_rule | The Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period. |
| ☐ | SV-264328r984313_rule | The VPN Gateway must employ organization-defined controls by type of denial of service (DoS) to achieve the DoS objective. |
| ☐ | SV-264329r1138038_rule | The VPN Gateway must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions. |
| ☐ | SV-264330r984319_rule | The VPN Gateway must establish organization-defined alternate communications paths for system operations organizational command and control. |
| ☐ | SV-264331r984329_rule | The VPN Gateway must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network. |
| ☐ | SV-264332r984332_rule | The VPN Gateway must configure OCSP to ensure revoked user certificates are prohibited from establishing an allowed session. |
| ☐ | SV-264333r984335_rule | The VPN Gateway must configure OCSP to ensure revoked machine certificates are prohibited from establishing an allowed session. |
| ☐ | SV-264334r984338_rule | The VPN Gateway providing authentication intermediary services must only accept end entity certificates (user or machine) issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs) for the establishment of VPN sessions. |
| ☐ | SV-264335r1138025_rule | The TLS VPN must be configured to limit authenticated client sessions to initial session source IP. |
| ☐ | SV-264336r1056131_rule | The VPN Gateway must use Always On VPN connections for remote computing. |
| ☐ | SV-279018r1138041_rule | The VPN Gateway must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
| ☐ | SV-279019r1138044_rule | The VPN Gateway must enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies. |
| ☐ | SV-279020r1138047_rule | The VPN Gateway must use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions. |
| ☐ | SV-279021r1138050_rule | The VPN Gateway must uniquely identify and authenticate source by organization, system, application, and/or individual for information transfer. |
| ☐ | SV-279022r1138053_rule | The VPN Gateway must uniquely identify and authenticate destination by organization, system, application, and/or individual for information transfer. |
| ☐ | SV-279023r1138056_rule | The VPN Gateway, when transferring information between different security domains, must apply the same security policy filtering to metadata as it applies to data payloads. |
| ☐ | SV-279024r1138059_rule | The VPN Gateway must implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission. |
| ☐ | SV-279025r1138062_rule | The VPN Gateway must dynamically associate security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined. |
| ☐ | SV-279026r1138065_rule | The VPN Gateway must use a FIPS-validated cryptographic module to provision digital signatures. |
| ☐ | SV-279027r1138068_rule | The VPN Gateway must use a FIPS-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality. |