STIGUI
V-239953CAT II — Medium severitySV-239953r916122_rule

The Cisco ASA must be configured to use NIST FIPS-validated cryptography for Internet Key Exchange (IKE) Phase 1.

Rule version CASA-VN-000170 · STIG v2 · 2024-08-22

Discussion

Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The VPN gateway must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.

Check

Verify the ASA uses a NIST FIPS-validated cryptography for IKE Phase 1 as shown in the example below.

crypto ikev2 policy 1 encryption aes-256

If the ASA is not configured to use NIST FIPS-validated cryptography for IKE Phase 1, this is a finding.

Fix

Configure the ASA to use NIST FIPS-validated cryptography for IKE Phase 1.

ASA1(config)# crypto ikev2 policy 1 ASA1(config-ikev2-policy)# encryption aes-256

Identifiers

Group ID
V-239953
Group title
SRG-NET-000510-VPN-002180
Rule ID
SV-239953r916122_rule
Check ID
C-43186r916120_chk
Fix ID
F-43145r916121_fix