SV-214669r695322_rule
V-214669
SRG-NET-000517
JUSX-VN-000002
CAT II
10
Set the lifetime (in seconds) of the IPsec proposal to 8 hours or less.
Example:
[edit]
set security ipsec proposal <P2-PROPOSAL-NAME> lifetime-seconds 28800
Review all IPsec security associations configured globally or within IPsec profiles on the VPN gateway and examine the configured idle time. The default is 3600.
[edit]
show security ipsec proposal
View the value of the lifetime-seconds option.
If the IPsec proposal lifetime-seconds are not renegotiated after 8 hours or less of idle time, this is a finding.
If the IPsec proposal lifetime-seconds is not configured, this is a finding.
V-214669
False
JUSX-VN-000002
Review all IPsec security associations configured globally or within IPsec profiles on the VPN gateway and examine the configured idle time. The default is 3600.
[edit]
show security ipsec proposal
View the value of the lifetime-seconds option.
If the IPsec proposal lifetime-seconds are not renegotiated after 8 hours or less of idle time, this is a finding.
If the IPsec proposal lifetime-seconds is not configured, this is a finding.
M
4009