SV-207193r608988_rule
V-207193
SRG-NET-000074
SRG-NET-000074-VPN-000250
CAT I
10
Configure the IPsec VPN to us the FIPS 140-2 DH group. The following command is an example of how to configure the IKE (phase 1) proposals.
The following groups are allowed for use in DoD:
DH Groups 14 (2048-bit MODP)
- 19 (256-bit Random ECP), 20 (384-bit Random ECP), 5 (1536-bit MODP), 24 (2048-bit MODP with 256-bit POS).
Verify all IKE proposals are set to use a FIPS-validated dh-group.
View the IKE options dh-group option.
If the IKE option is not set to a FIPS 140-2 validated dh-group, this is a finding.
V-207193
False
SRG-NET-000074-VPN-000250
Verify all IKE proposals are set to use a FIPS-validated dh-group.
View the IKE options dh-group option.
If the IKE option is not set to a FIPS 140-2 validated dh-group, this is a finding.
M
2920