SV-214678r385561_rule
V-214678
SRG-NET-000512
JUSX-VN-000011
CAT II
10
Allow IKE as a host-inbound service within the security zone associated with the IKE gateway’s external interface configuration. Assuming the use of ge-0/0/0, which is associated with the “untrust” zone, the following is an example of zone configuration.
[edit]
set security zones security-zone untrust host-inbound-traffic system-services ike
Verify a security zone is configured for the VPN Internet Key Exchange (IKE) service.
[edit]
show security zones
If a security zone is not configured for the IKE traffic, this is a finding.
V-214678
False
JUSX-VN-000011
Verify a security zone is configured for the VPN Internet Key Exchange (IKE) service.
[edit]
show security zones
If a security zone is not configured for the IKE traffic, this is a finding.
M
4009