SV-214674r382783_rule
V-214674
SRG-NET-000062
JUSX-VN-000007
CAT II
10
The following command is an example of how to configure the IKE (phase 1) proposals. The following groups are allowed for use in DoD:
DH Groups 14 (2048-bit MODP)
- 19 (256-bit Random ECP), 20 (384-bit Random ECP), 5 (1536-bit MODP), 24 (2048-bit MODP with 256-bit POS).
Example:
[edit]
set security ike proposal <P1-PROPOSAL-NAME> dh-group group14
Verify all IKE proposals are set to use a FIPS-validated dh-group.
[edit]
show security ike <P1-PROPOSAL-NAME>
View the IKE options dh-group option.
If the IKE option is not set to a FIPS-140-2 validated dh-group, this is a finding.
V-214674
False
JUSX-VN-000007
Verify all IKE proposals are set to use a FIPS-validated dh-group.
[edit]
show security ike <P1-PROPOSAL-NAME>
View the IKE options dh-group option.
If the IKE option is not set to a FIPS-140-2 validated dh-group, this is a finding.
M
4009