SV-214680r385561_rule
V-214680
SRG-NET-000512
JUSX-VN-000013
CAT II
10
Configure the VPN gateway to ensure PFS is enabled. The following commands configure an IPsec policy, enabling PFS using Diffie-Hellman group 14 and associates the IPsec proposal configured in the previous example.
[edit]
set security ipsec policy <IPSEC-POLICY> perfect-forward-secrecy keys group14
set security ipsec policy <IPSEC-POLICY> proposals <IPSEC-PROPOSAL>
Examine all IPsec profiles to verify PFS is enabled.
[edit]
show security ipsec policy
If PFS is not configured, this is a finding.
V-214680
False
JUSX-VN-000013
Examine all IPsec profiles to verify PFS is enabled.
[edit]
show security ipsec policy
If PFS is not configured, this is a finding.
M
4009