SV-214693r383494_rule
V-214693
SRG-NET-000355
JUSX-VN-000026
CAT II
10
The following example commands configure the IKE (phase 1) proposals. Use certificates instead of pre-shared keys to establish the IKE phase 1 tunnel.
This proposal requires AES 256-bit encryption
set security ike proposal p1-proposal authentication-method rsa-signatures
Verify the all IKE proposals are set to use the AES encryption algorithm.
[edit]
show security ike
View the value of the authentication-method for each defined proposal.
If the value of the authentication-method for each defined proposal is not set to use AES, this is a finding.
V-214693
False
JUSX-VN-000026
Verify the all IKE proposals are set to use the AES encryption algorithm.
[edit]
show security ike
View the value of the authentication-method for each defined proposal.
If the value of the authentication-method for each defined proposal is not set to use AES, this is a finding.
M
4009