SV-214675r382846_rule
V-214675
SRG-NET-000063
JUSX-VN-000008
CAT II
10
The following example commands configure the IPSec proposal.
set security ipsec proposal <IPSEC-PROPOSAL-NAME> authentication-algorithm <hmac-sha-256-128 | hmac-sha-256-96 | hmac-sha1-96>
Verify all IPSec proposals are set to use the sha-256 hashing algorithm.
[edit]
show security ipsec proposal <IPSEC-PROPOSAL-NAME>
View the value of the encryption algorithm for each defined proposal.
If the value of the encryption algorithm option for all defined proposals is not set to use SHA1 or greater, this is a finding.
V-214675
False
JUSX-VN-000008
Verify all IPSec proposals are set to use the sha-256 hashing algorithm.
[edit]
show security ipsec proposal <IPSEC-PROPOSAL-NAME>
View the value of the encryption algorithm for each defined proposal.
If the value of the encryption algorithm option for all defined proposals is not set to use SHA1 or greater, this is a finding.
M
4009