SV-234253r628798_rule
V-234253
SRG-APP-000014
CVAD-VD-000030
CAT I
10
Implement a DoD-approved VPN or gateway/proxy that will authenticate user access and tunnel/proxy traffic to the Windows VDA. Ensure the VPN or gateway/proxy is configured to authenticate the user before accessing the environment, and meets the DoD encryption requirements, such as FIPS 140-2, for the environment.
A DoD approved VPN, or gateway/proxy, must be leveraged to access the Windows VDA from a remote network. This VPN, or gateway, must handle user authentication and tunneling of Citrix traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment.
If no VPN, or gateway/proxy, is used for remote access to the VDA, this is a finding.
If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to the VDA, this is a finding.
If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.
V-234253
False
CVAD-VD-000030
A DoD approved VPN, or gateway/proxy, must be leveraged to access the Windows VDA from a remote network. This VPN, or gateway, must handle user authentication and tunneling of Citrix traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment.
If no VPN, or gateway/proxy, is used for remote access to the VDA, this is a finding.
If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to the VDA, this is a finding.
If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.
M
5265