SV-214691r383878_rule
V-214691
SRG-NET-000510
JUSX-VN-000024
CAT II
10
The following example commands configure the IKE (phase 1) proposal.
[edit]
set security ike proposal <P1-PROPOSAL> authentication-method rsa-signatures
set security ike proposal p1-proposal dh-group group14
set security ike proposal p1-proposal authentication-algorithm sha-256
set security ike proposal p1-proposal encryption-algorithm aes-256-cbc
set security ike proposal p1-proposal lifetime-seconds 86400
Verify all Internet Key Exchange (IKE) proposals are set to use the AES encryption algorithm.
[edit]
show security ike
View the value of the encryption algorithm for each defined proposal.
If the value of the authentication method and other options are not set to use FIPS-compliant values, this is a finding.
V-214691
False
JUSX-VN-000024
Verify all Internet Key Exchange (IKE) proposals are set to use the AES encryption algorithm.
[edit]
show security ike
View the value of the encryption algorithm for each defined proposal.
If the value of the authentication method and other options are not set to use FIPS-compliant values, this is a finding.
M
4009