SV-214683r385486_rule
V-214683
SRG-NET-000132
JUSX-VN-000016
CAT II
10
For site-to-site VPNs, configure the Juniper SRX to use IKEv2 only.
[edit]
set security ike gateway <VPN-GATEWAY> address <GW-IP-ADDRESS>
set security ike gateway <VPN-GATEWAY> version v2-only
Verify only IKEv2 is used for the IKE security configuration on all configured gateways. Use of IKEv1 mitigates the risk to a CAT III finding.
Show security ike gateway <VPN-GATEWAY>
If IKEv2 is not used for IKE associations, this is a finding.
V-214683
False
JUSX-VN-000016
Verify only IKEv2 is used for the IKE security configuration on all configured gateways. Use of IKEv1 mitigates the risk to a CAT III finding.
Show security ike gateway <VPN-GATEWAY>
If IKEv2 is not used for IKE associations, this is a finding.
M
4009