Virtual Private Network (VPN) Security Requirements Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- SRG-NET-000019-VPN-000040
- Vuln IDs
-
- V-97041
- Rule IDs
-
- SV-106179r1_rule
Checks: C-95877r1_chk
Verify the VPN Gateway has an inbound and outbound traffic security policy which is in compliance with information flow control policies (e.g., IPsec policy configuration). Review network device configurations and topology diagrams. Verify encapsulated or encrypted traffic received from other enclaves with different security policies terminate at the perimeter for filtering and content inspection by a firewall and IDPS before gaining access to the private network. If the VPN Gateway does not ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies, this is a finding.
Fix: F-102721r1_fix
Configure the VPN Gateway to ensure inbound and outbound traffic is configured with a security policy in compliance with information flow control policies (e.g., IPsec policy configuration). Also, configure the VPN gateway to forward encapsulated or encrypted traffic received from other enclaves with different security policies to the perimeter firewall and IDPS before traffic is passed to the private network.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- SRG-NET-000041-VPN-000110
- Vuln IDs
-
- V-97043
- Rule IDs
-
- SV-106181r1_rule
Checks: C-95879r1_chk
If the user/remote client connection banner is the same as the banner configured as part of the NDM SRG, then this is not applicable. Determine if the network device is configured to present a DoD-approved banner that is formatted in accordance with DoD policy. If the Remote Access VPN Gateway or VPN client does not display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the network, this is a finding.
Fix: F-102723r1_fix
Configure the Remote Access VPN to display the Standard Mandatory DoD Notice and Consent Banner in accordance with DoD policy before granting access to the device. Use the following verbiage for applications that can accommodate banners of 1300 characters: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." Use the following verbiage for operating systems that have severe limitations on the number of characters that can be displayed in the banner: "I've read & consent to terms in IS user agreem't."
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- SRG-NET-000042-VPN-000120
- Vuln IDs
-
- V-97045
- Rule IDs
-
- SV-106183r1_rule
Checks: C-95881r1_chk
If the user/remote client connection banner is the same as the banner configured as part of the NDM SRG, then this is not applicable. Verify the ALG retains the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and takes explicit actions to log on for further access. If the Remote Access VPN Gateway and/or client does not retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access, this is a finding.
Fix: F-102725r1_fix
Configure the Remote Access VPN Gateway and/or client to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-001384
- Version
- SRG-NET-000043-VPN-000130
- Vuln IDs
-
- V-97047
- Rule IDs
-
- SV-106185r1_rule
Checks: C-95883r1_chk
Verify the publicly accessible VPN Gateway displays the Standard Mandatory DoD Notice and Consent Banner before granting access to the system. The banner must be formatted in accordance with DTM-08-060. Use the following verbiage for network elements that can accommodate banners of 1300 characters: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." Use the following verbiage for operating systems that have severe limitations on the number of characters that can be displayed in the banner: "I've read & consent to terms in IS user agreem't." If the publicly accessible VPN Gateway does not display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system, this is a finding.
Fix: F-102727r1_fix
Configure the publicly accessible VPN Gateway to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.
- RMF Control
- AC-9
- Severity
- L
- CCI
- CCI-000053
- Version
- SRG-NET-000049-VPN-000150
- Vuln IDs
-
- V-97049
- Rule IDs
-
- SV-106187r1_rule
Checks: C-95885r1_chk
Determine if the VPN Gateway is either configured to notify the administrator of the number of unsuccessful login attempts since the last successful login or configured to use an authentication server which would perform this function. If the administrator is not notified of the number of unsuccessful login attempts since the last successful login, this is a finding. If the VPN Gateway does not notify the user, upon successful logon (access), of the number of unsuccessful logon (access) attempts since the last successful logon (access), this is a finding.
Fix: F-102729r1_fix
Configure the VPN Gateway to notify the user, upon successful logon (access), of the number of unsuccessful logon (access) attempts since the last successful logon (access).
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- SRG-NET-000053-VPN-000170
- Vuln IDs
-
- V-97051
- Rule IDs
-
- SV-106189r1_rule
Checks: C-95887r1_chk
Inspect the VPN Gateway configuration. Verify the number of concurrent sessions for user accounts to 1 or to an organization-defined number (defined in the SSP). If the VPN Gateway does not limit the number of concurrent sessions for user accounts to 1 or to an organization-defined number, this is a finding.
Fix: F-102731r1_fix
Configure the VPN Gateway to limit the number of concurrent sessions for user accounts to 1 or to an organization-defined number, as documented in the SSP.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- SRG-NET-000062-VPN-000200
- Vuln IDs
-
- V-97053
- Rule IDs
-
- SV-106191r1_rule
Checks: C-95889r1_chk
Verify the TLS VPN Gateway is configured to use TLS 1.2 or higher to protect the confidentiality of sensitive data during transmission. If the TLS VPN Gateway does not use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during transmission, this is a finding.
Fix: F-102733r1_fix
Configure the TLS VPN Gateway to use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data for transmission.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- SRG-NET-000063-VPN-000210
- Vuln IDs
-
- V-97055
- Rule IDs
-
- SV-106193r1_rule
Checks: C-95891r1_chk
Verify the remote access VPN Gateway uses a digital signature generated using FIPS-validated algorithms and an approved hash function to protect the integrity of remote access sessions. If the remote access VPN Gateway does not use a digital signature generated using FIPS-validated algorithms and an approved hash function to protect the integrity of remote access sessions, this is a finding.
Fix: F-102735r1_fix
Configure the remote access VPN Gateway to use a digital signature generated using FIPS-validated algorithms and an approved hash function to protect the integrity of remote access sessions.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- SRG-NET-000063-VPN-000220
- Vuln IDs
-
- V-97057
- Rule IDs
-
- SV-106195r1_rule
Checks: C-95893r1_chk
Verify the VPN Gateway uses IPsec with SHA-1 or greater for hashing to protect the integrity of remote access sessions. If the VPN Gateway does not use IPsec with SHA-1 or greater for hashing to protect the integrity of remote access sessions, this is a finding.
Fix: F-102737r1_fix
Configure the VPN Gateway to use IPsec with SHA-1 or greater for hashing to protect the integrity of remote access sessions.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- SRG-NET-000074-VPN-000250
- Vuln IDs
-
- V-97059
- Rule IDs
-
- SV-106197r1_rule
Checks: C-95895r1_chk
Verify all IKE proposals are set to use a FIPS-validated dh-group. View the IKE options dh-group option. If the IKE option is not set to a FIPS 140-2 validated dh-group, this is a finding.
Fix: F-102739r1_fix
Configure the IPsec VPN to us the FIPS 140-2 DH group. The following command is an example of how to configure the IKE (phase 1) proposals. The following groups are allowed for use in DoD: DH Groups 14 (2048-bit MODP) - 19 (256-bit Random ECP), 20 (384-bit Random ECP), 5 (1536-bit MODP), 24 (2048-bit MODP with 256-bit POS).
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000130
- Version
- SRG-NET-000077-VPN-000280
- Vuln IDs
-
- V-97061
- Rule IDs
-
- SV-106199r1_rule
Checks: C-95899r1_chk
Verify the VPN Gateway generates log records containing information to establish what type of events occurred. If the VPN Gateway does not generate log records containing information to establish what type of events occurred, this is a finding.
Fix: F-102743r1_fix
Configure the VPN Gateway to generate log records containing information to establish what type of events occurred.
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000131
- Version
- SRG-NET-000078-VPN-000290
- Vuln IDs
-
- V-97063
- Rule IDs
-
- SV-106201r1_rule
Checks: C-95901r1_chk
Configure the VPN Gateway generates log records containing information to establish when (date and time) the events occurred. If the VPN Gateway does not generate log records containing information to establish when (date and time) the events occurred, this is a finding.
Fix: F-102745r1_fix
Configure the VPN Gateway to generate log records containing information to establish when (date and time) the events occurred.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001487
- Version
- SRG-NET-000079-VPN-000300
- Vuln IDs
-
- V-97065
- Rule IDs
-
- SV-106203r1_rule
Checks: C-95903r1_chk
Verify the VPN Gateway generates log records containing information that establishes the identity of any individual or process associated with the event. If the VPN Gateway does not generate log records containing information that establishes the identity of any individual or process associated with the event, this is a finding.
Fix: F-102747r1_fix
Configure the VPN Gateway to generate log records containing information that establishes the identity of any individual or process associated with the event.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- SRG-NET-000088-VPN-000310
- Vuln IDs
-
- V-97067
- Rule IDs
-
- SV-106205r1_rule
Checks: C-95905r1_chk
Verify the VPN Gateway generates log records containing information to establish where the events occurred. If the VPN Gateway does not generate log records containing information to establish where the events occurred, this is a finding.
Fix: F-102749r1_fix
Configure the VPN Gateway to generates log records containing information to establish where the events occurred.
- RMF Control
- AU-3
- Severity
- L
- CCI
- CCI-000133
- Version
- SRG-NET-000089-VPN-000330
- Vuln IDs
-
- V-97069
- Rule IDs
-
- SV-106207r1_rule
Checks: C-95907r1_chk
Verify the VPN Gateway generates log records containing information to establish the source of the events. If the VPN Gateway does not generate log records containing information to establish the source of the events, this is a finding.
Fix: F-102751r1_fix
Configure the VPN Gateway to generate log records containing information to establish the source of the events.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- SRG-NET-000091-VPN-000350
- Vuln IDs
-
- V-97071
- Rule IDs
-
- SV-106209r1_rule
Checks: C-95909r1_chk
Examine the log configuration on the VPN Gateway or view several alert events on the organization's central audit server. Alternatively, examine the Central Log Server to see if it contains information about success or failure of client connection attempts or other events. If the traffic log entries do not include the success or failure of connection attempts and other events, this is a finding.
Fix: F-102753r1_fix
Configure the VPN Gateway to generate log entries containing information to establish the outcome of the events, such as, at a minimum, the success or failure of the client connection attempts.
- RMF Control
- AU-9
- Severity
- L
- CCI
- CCI-000162
- Version
- SRG-NET-000098-VPN-000370
- Vuln IDs
-
- V-97073
- Rule IDs
-
- SV-106211r1_rule
Checks: C-95911r1_chk
Verify the VPN Gateway protects log information from unauthorized read access if all or some of this data is stored locally. If the VPN Gateway does not protect log information from unauthorized read access if all or some of this data is stored locally, this is a finding.
Fix: F-102755r1_fix
Configure the VPN Gateway to protect log information from unauthorized read access if all or some of this data is stored locally.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- SRG-NET-000099-VPN-000380
- Vuln IDs
-
- V-97075
- Rule IDs
-
- SV-106213r1_rule
Checks: C-95913r1_chk
Verify the VPN Gateway log is configured to protect audit information from unauthorized modification when stored locally. The VPN Gateway log must protect audit information from unauthorized modification when stored locally, this is a finding.
Fix: F-102757r1_fix
Configure the VPN Gateway log to protect audit information from unauthorized modification when stored locally. The method used depends on system architecture and design. Examples: ensuring log files receive the proper file system permissions and limiting log data locations.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- SRG-NET-000100-VPN-000390
- Vuln IDs
-
- V-97077
- Rule IDs
-
- SV-106215r1_rule
Checks: C-95915r1_chk
Verify the VPN Gateway is configured to protect audit information from unauthorized deletion when stored locally. If the VPN Gateway does not protect audit information from unauthorized deletion when stored locally, this is a finding.
Fix: F-102759r1_fix
Configure the VPN Gateway to protect audit information from unauthorized deletion when stored locally. Ensure log files receive the proper file system permissions and limiting log data locations.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-NET-000132-VPN-000450
- Vuln IDs
-
- V-97079
- Rule IDs
-
- SV-106217r1_rule
Checks: C-95917r1_chk
View the configured security services. Compare the services that are enabled, including the port, services, protocols, and functions. If functions, ports, protocols, and services identified on the PPSM CAL are not disabled, this is a finding.
Fix: F-102761r1_fix
Ensure functions, ports, protocols, and services identified on the PPSM CAL are not used for system services configuration. View the configured security services. Compare the services that are enabled, including the port, services, protocols, and functions. Consult the product knowledge base and configuration guides to determine the commands for disabling each port, protocols, services, or functions that is not in compliance with the PPSM CAL and vulnerability assessments.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-NET-000132-VPN-000460
- Vuln IDs
-
- V-97081
- Rule IDs
-
- SV-106219r1_rule
Checks: C-95919r1_chk
Verify the IPsec VPN Gateway uses IKEv2 for IPsec VPN security associations. If the IPsec VPN Gateway must use IKEv2 for IPsec VPN security associations, this is a finding.
Fix: F-102763r1_fix
Configure the IPsec VPN Gateway to use IKEv2 for IPsec VPN security associations.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-NET-000132-VPN-000470
- Vuln IDs
-
- V-97083
- Rule IDs
-
- SV-106221r1_rule
Checks: C-95921r1_chk
Verify the VPN Gateway is configured to prohibit PPTP and L2F. If the VPN Gateway does not be configured to prohibit PPTP and L2F, this is a finding.
Fix: F-102765r1_fix
Configure the VPN Gateway to prohibit PPTP and L2F.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-NET-000132-VPN-000480
- Vuln IDs
-
- V-97085
- Rule IDs
-
- SV-106223r1_rule
Checks: C-95923r1_chk
If L2TP communications protocol is not used, this is not applicable. Verify the VPN Gateway or another network element (e.g., firewall) is configure to block or deny L2TP packets with a destination address within the private network of the enclave. If L2TP communications are allowed to cross the security boundary into the private network of the enclave, this is a finding.
Fix: F-102767r1_fix
If L2TP is used for encapsulation, configure the VPN Gateway or other network element to block or deny this communications protocol unencrypted L2TP packets across the security boundary and into the private network of the enclave.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- SRG-NET-000138-VPN-000490
- Vuln IDs
-
- V-97087
- Rule IDs
-
- SV-106225r1_rule
Checks: C-95925r1_chk
Verify the VPN Gateway is configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). If the VPN Gateway does not uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users), this is a finding.
Fix: F-102769r1_fix
Configure the VPN Gateway to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000766
- Version
- SRG-NET-000140-VPN-000500
- Vuln IDs
-
- V-97089
- Rule IDs
-
- SV-106227r1_rule
Checks: C-95927r1_chk
Verify the VPN Gateway uses multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts. If the VPN Gateway does not use multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts, this is a finding.
Fix: F-102771r1_fix
Configure the VPN Gateway to use multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001939
- Version
- SRG-NET-000145-VPN-000510
- Vuln IDs
-
- V-97091
- Rule IDs
-
- SV-106229r1_rule
Checks: C-95929r1_chk
Verify the VPN Client implements multifactor authentication for network access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access. If the VPN Client does not implement multifactor authentication for network access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access, this is a finding.
Fix: F-102773r1_fix
Configure the VPN Client to implement multifactor authentication for network access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001942
- Version
- SRG-NET-000147-VPN-000520
- Vuln IDs
-
- V-97093
- Rule IDs
-
- SV-106231r1_rule
Checks: C-95931r1_chk
Verify the TLS VPN Gateway is configured to use replay-resistant authentication mechanisms for network access to non-privileged accounts. If the TLS VPN is not configured to use replay-resistant authentication mechanisms for network access to non-privileged accounts, this is a finding.
Fix: F-102775r1_fix
Configure the TLS VPN Gateway to use replay-resistant authentication mechanisms for network access to non-privileged accounts.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001942
- Version
- SRG-NET-000147-VPN-000530
- Vuln IDs
-
- V-97095
- Rule IDs
-
- SV-106233r1_rule
Checks: C-95933r1_chk
Verify the IPsec VPN Gateway uses anti-replay mechanisms for security associations. If the IPsec VPN Gateway does not use anti-replay mechanisms for security associations, this is a finding.
Fix: F-102777r1_fix
Configure the IPsec VPN Gateway to use anti-replay mechanisms for security associations.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000778
- Version
- SRG-NET-000148-VPN-000540
- Vuln IDs
-
- V-97097
- Rule IDs
-
- SV-106235r1_rule
Checks: C-95935r1_chk
Verify the VPN Gateway uniquely identifies all network-connected endpoint devices before establishing a connection. If the VPN Gateway does not uniquely identify all network-connected endpoint devices before establishing a connection, this is a finding.
Fix: F-102779r1_fix
Configure the VPN Gateway to uniquely identify all network-connected endpoint devices before establishing a connection.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- SRG-NET-000164-VPN-000560
- Vuln IDs
-
- V-97099
- Rule IDs
-
- SV-106237r1_rule
Checks: C-95937r1_chk
Verify the VPN Gateway to use PKI-based authentication that validates certificates by constructing a certification path (which includes status information) to an accepted trust anchor. If PKI-based authentication does not validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor, this is a finding.
Fix: F-102781r1_fix
Configure the VPN Gateway to use PKI-based authentication that validates certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- SRG-NET-000165-VPN-000570
- Vuln IDs
-
- V-97101
- Rule IDs
-
- SV-106239r1_rule
Checks: C-95939r1_chk
If PKI-based authentication is not being used for device authentication, this is not applicable. Verify the site-to-site VPN that uses certificate-based device authentication uses a FIPS-compliant key management process. If the site-to-site VPN that uses certificate-based device authentication does not use a FIPS-compliant key management process, this is a finding.
Fix: F-102783r1_fix
Configure the site-to-site VPN that uses certificate-based device authentication to use a FIPS-compliant key management process.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- SRG-NET-000166-VPN-000580
- Vuln IDs
-
- V-97103
- Rule IDs
-
- SV-106241r1_rule
Checks: C-95941r1_chk
Verify the Remote Access VPN Gateway is configured to use a physically separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication. If the Remote Access VPN Gateway does not use a separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication, this is a finding.
Fix: F-102785r1_fix
Configure the Remote Access VPN Gateway to use a separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- SRG-NET-000166-VPN-000590
- Vuln IDs
-
- V-97113
- Rule IDs
-
- SV-106251r1_rule
Checks: C-95953r1_chk
Verify the VPN Gateway maps the authenticated identity to the user account for PKI-based authentication. If the VPN Gateway does not map the authenticated identity to the user account for PKI-based authentication, this is a finding.
Fix: F-102797r1_fix
Configure the VPN Gateway to map the authenticated identity to the user account for PKI-based authentication.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SRG-NET-000168-VPN-000600
- Vuln IDs
-
- V-97115
- Rule IDs
-
- SV-106253r1_rule
Checks: C-95955r1_chk
Verify the VPN Gateway uses FIPS-validated SHA-1 or higher hash function to protect the integrity of hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, hash-only applications, and digital signature verification (legacy use only). If the VPN Gateway does not use FIPS-validated SHA-1 or higher hash function to protect the integrity of hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, hash-only applications, and digital signature verification (legacy use only), this is a finding.
Fix: F-102799r1_fix
Configure the VPN Gateway to use FIPS-validated SHA-1 or higher hash function to protect the integrity of hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, hash-only applications, and digital signature verification (legacy use only).
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- SRG-NET-000169-VPN-000610
- Vuln IDs
-
- V-97117
- Rule IDs
-
- SV-106255r1_rule
Checks: C-95957r1_chk
Configure the VPN Gateway to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users). If the VPN Gateway does not uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users), this is a finding.
Fix: F-102801r1_fix
Configure the VPN Gateway to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001097
- Version
- SRG-NET-000205-VPN-000710
- Vuln IDs
-
- V-97119
- Rule IDs
-
- SV-106257r1_rule
Checks: C-95959r1_chk
Verify the VPN Gateway routes sessions to an IDPS for inspection. If the VPN Gateway is not configured to route sessions to an IDPS for inspection, this is a finding.
Fix: F-102803r1_fix
Configure the VPN Gateway to route sessions to an IDPS for inspection.
- RMF Control
- SC-10
- Severity
- L
- CCI
- CCI-001133
- Version
- SRG-NET-000213-VPN-000720
- Vuln IDs
-
- V-97121
- Rule IDs
-
- SV-106259r1_rule
Checks: C-95961r1_chk
Verify the VPN Gateway terminates all network connections associated with a communications session at the end of the session. If the VPN Gateway does not terminate all network connections associated with a communications session at the end of the session, this is a finding.
Fix: F-102805r1_fix
Configure the VPN Gateway to terminate all network connections associated with a communications session at the end of the session.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001184
- Version
- SRG-NET-000230-VPN-000770
- Vuln IDs
-
- V-97123
- Rule IDs
-
- SV-106261r1_rule
Checks: C-95963r1_chk
Verify the VPN Gateway uses FIPS 140-2 compliant mechanisms for authentication to a cryptographic module. If the VPN Gateway does not use FIPS 140-2 compliant mechanisms for authentication to a cryptographic module, this is a finding.
Fix: F-102807r1_fix
Configure the VPN Gateway to use FIPS 140-2 compliant mechanisms for authentication to a cryptographic module.
- RMF Control
- SC-23
- Severity
- H
- CCI
- CCI-001184
- Version
- SRG-NET-000230-VPN-000780
- Vuln IDs
-
- V-97125
- Rule IDs
-
- SV-106263r1_rule
Checks: C-95965r1_chk
Verify the IPsec VPN Gateway uses IKE with SHA1 or greater to protect the authenticity of communications sessions. If the IPsec VPN Gateway is not configured to use IKE with SHA1 or greater to protect the authenticity of communications sessions, this is a finding.
Fix: F-102809r1_fix
Configure the IPsec VPN Gateway to use IKE with SHA1 or greater to protect the authenticity of communications sessions.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001185
- Version
- SRG-NET-000231-VPN-000790
- Vuln IDs
-
- V-97127
- Rule IDs
-
- SV-106265r1_rule
Checks: C-95967r1_chk
Verify the VPN Gateway invalidates session identifiers upon user logoff or other session termination. If the VPN Gateway does not invalidate session identifiers upon user logoff or other session termination, this is a finding.
Fix: F-102811r1_fix
Configure the VPN Gateway to invalidate session identifiers upon user logoff or other session termination.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001664
- Version
- SRG-NET-000233-VPN-000800
- Vuln IDs
-
- V-97129
- Rule IDs
-
- SV-106267r1_rule
Checks: C-95969r1_chk
Verify the VPN Gateway recognizes only system-generated session identifiers. If the VPN Gateway does not recognize only system-generated session identifiers, this is a finding.
Fix: F-102813r1_fix
Configure the VPN Gateway to recognize only system-generated session identifiers.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001188
- Version
- SRG-NET-000234-VPN-000810
- Vuln IDs
-
- V-97131
- Rule IDs
-
- SV-106269r1_rule
Checks: C-95971r1_chk
Verify the VPN Gateway generates unique session identifiers using FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm. If the VPN Gateway does not generate unique session identifiers using FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm, this is a finding.
Fix: F-102815r1_fix
Configure the VPN Gateway to generate unique session identifiers using FIPS-validated Random Number Generator (RNG) based on the Deterministic Random Bit Generators (DRBG) algorithm.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- SRG-NET-000235-VPN-000820
- Vuln IDs
-
- V-97133
- Rule IDs
-
- SV-106271r1_rule
Checks: C-95973r1_chk
Verify the VPN Gateway is configured to fail to a secure state if system initialization fails, shutdown fails, or aborts fail. If the VPN Gateway does not fail to a secure state if system initialization fails, shutdown fails, or aborts fail, this is a finding.
Fix: F-102817r1_fix
Configure the VPN Gateway to fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- SRG-NET-000313-VPN-001050
- Vuln IDs
-
- V-97135
- Rule IDs
-
- SV-106273r1_rule
Checks: C-95975r1_chk
Verify the VPN Gateway is configured to perform an organization-defined action if the audit reveals unauthorized activity. If the VPN Gateway does not be configured to perform an organization-defined action if the audit reveals unauthorized activity, this is a finding.
Fix: F-102819r1_fix
Configure the VPN Gateway to be configured to perform an organization-defined action if the audit reveals unauthorized activity.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002322
- Version
- SRG-NET-000314-VPN-001060
- Vuln IDs
-
- V-97137
- Rule IDs
-
- SV-106275r1_rule
Checks: C-95977r1_chk
Configure the VPN Gateway for functionality, such as automatic disconnect (or user-initiated disconnect) in case of adverse information based on an indicator of compromise or attack. Configure authorized system administrator accounts to allow them to disconnect or disable remote access to remove user under circumstances defined in the VPN SSP. If the VPN Gateway administrator accounts or security policy is not configured to allow the system administrator to immediately disconnect or disable remote access to devices and/or users when needed, this is a finding.
Fix: F-102821r1_fix
Configure the VPN Gateway for functionality, such as automatic disconnect (or user-initiated disconnect) in case of adverse information based on an indicator of compromise or attack. Configure authorized system administrator accounts to allow them to disconnect or disable remote access to remove user under circumstances defined in the VPN SSP.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- SRG-NET-000317-VPN-001090
- Vuln IDs
-
- V-97139
- Rule IDs
-
- SV-106277r1_rule
Checks: C-95979r1_chk
Verify all IKE proposals are set to use the AES encryption algorithm. View the value of the encryption algorithm for each defined proposal. If the value of the encryption algorithm for any IKE proposal is not set to use an AES algorithm, this is a finding.
Fix: F-102823r1_fix
Configure the IPsec Gateway to use AES with IKE. The option on the IKE Phase 1 proposal may also be configured to use the aes-128-cbc, aes-192-cbc, or aes-256-cbc algorithms.
- RMF Control
- AC-24
- Severity
- M
- CCI
- CCI-002353
- Version
- SRG-NET-000320-VPN-001120
- Vuln IDs
-
- V-97141
- Rule IDs
-
- SV-106279r1_rule
Checks: C-95981r1_chk
Verify the VPN Gateway transmits organization-defined access authorization information using FIPS 140-2-validated cryptography to a compliant authentication server, which enforces access control decisions. If the VPN Gateway does not transmit organization-defined access authorization information using FIPS 140-2-validated cryptography to a compliant authentication server, which enforces access control decisions, this is a finding.
Fix: F-102825r1_fix
Configure the VPN Gateway to transmit organization-defined access authorization information using FIPS 140-2-validated cryptography to a compliant authentication server, which enforces access control decisions.
- RMF Control
- AC-9
- Severity
- L
- CCI
- CCI-002250
- Version
- SRG-NET-000330-VPN-001220
- Vuln IDs
-
- V-97143
- Rule IDs
-
- SV-106281r1_rule
Checks: C-95983r1_chk
Verity the VPN Gateway notifies the user, upon successful logon (access), of the organization-defined information to be included in addition to the date and time of the last logon (access). If the VPN Gateway does not notify the user, upon successful logon (access), of the organization-defined information to be included in addition to the date and time of the last logon (access), this is a finding.
Fix: F-102827r1_fix
Configure the VPN Gateway to notify the user, upon successful logon (access), of the organization-defined information to be included in addition to the date and time of the last logon (access).
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001844
- Version
- SRG-NET-000333-VPN-001250
- Vuln IDs
-
- V-97145
- Rule IDs
-
- SV-106283r1_rule
Checks: C-95985r1_chk
Verify the VPN Gateway provides centralized management and configuration of the content to be captured in log records generated by all network components. If the VPN Gateway does not provide centralized management and configuration of the content to be captured in log records generated by all network components, this is a finding.
Fix: F-102829r1_fix
Configure the VPN Gateway to provide centralized management and configuration of the content to be captured in log records generated by all network components.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- SRG-NET-000334-VPN-001260
- Vuln IDs
-
- V-97147
- Rule IDs
-
- SV-106285r1_rule
Checks: C-95987r1_chk
Verify the VPN Gateway off-loads log records onto a different system or media than the system being audited. If the VPN Gateway does not off-load audit records onto a different system or media than the system being audited, this is a finding.
Fix: F-102831r1_fix
Configure the VPN Gateway to off-load audit records onto a different system or media than the system being audited.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001858
- Version
- SRG-NET-000335-VPN-001270
- Vuln IDs
-
- V-97149
- Rule IDs
-
- SV-106287r1_rule
Checks: C-95989r1_chk
Verify the VPN Gateway generates a log record or an SNMP trap that can be forwarded as an alert to, at a minimum, the SCA and ISSO, of all log failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server. If the VPN Gateway does not generate a log record or an SNMP trap that can be forwarded as an alert to, at a minimum, the SCA and ISSO, of all log failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server, this is a finding.
Fix: F-102833r1_fix
Configure the VPN Gateway to generate a log record or an SNMP trap that can be forwarded as an alert to, at a minimum, the SCA and ISSO, of all log failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001861
- Version
- SRG-NET-000336-VPN-001280
- Vuln IDs
-
- V-97151
- Rule IDs
-
- SV-106289r1_rule
Checks: C-95991r1_chk
Verify that in the event that communications with the Central Log Server is lost, the VPN Gateway is configured to continue to queue traffic log records locally. If the VPN Gateway does not continue to queue traffic log records locally when communications with the Central Log Server is lost, this is a finding.
Fix: F-102835r1_fix
Configure the VPN Gateway to continue to queue traffic log records locally when communications with the Central Log Server is lost.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- SRG-NET-000337-VPN-001290
- Vuln IDs
-
- V-97153
- Rule IDs
-
- SV-106291r1_rule
Checks: C-95993r1_chk
Verify the IPsec VPN Gateway renegotiates the security association after 8 hours or less, or an organization-defined period. If the IPsec VPN Gateway does not renegotiate the security association after 8 hours or less, or an organization-defined period, this is a finding.
Fix: F-102837r1_fix
Configure the IPsec VPN Gateway to renegotiate the security association after 8 hours or less, or an organization-defined period.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- SRG-NET-000337-VPN-001300
- Vuln IDs
-
- V-97155
- Rule IDs
-
- SV-106293r1_rule
Checks: C-95995r1_chk
Verify the VPN Gateway renegotiates the security association after 24 hours or less or as defined by the organization. If the VPN Gateway does not renegotiate the security association after 24 hours or less or as defined by the organization, this is a finding.
Fix: F-102839r1_fix
Configure the VPN Gateway to renegotiate the security association after 24 hours or less or as defined by the organization.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001953
- Version
- SRG-NET-000341-VPN-001350
- Vuln IDs
-
- V-97157
- Rule IDs
-
- SV-106295r1_rule
Checks: C-95997r1_chk
Verify the VPN Gateway accepts Personal Identity Verification (PIV) credentials. If the VPN Gateway does not accept Personal Identity Verification (PIV) credentials, this is a finding.
Fix: F-102841r1_fix
Configure the VPN Gateway to accept Personal Identity Verification (PIV) credentials.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001954
- Version
- SRG-NET-000342-VPN-001360
- Vuln IDs
-
- V-97159
- Rule IDs
-
- SV-106297r1_rule
Checks: C-95999r1_chk
Verify the VPN Gateway electronically verifies Personal Identity Verification (PIV) credentials. If the VPN Gateway does not electronically verify Personal Identity Verification (PIV) credentials, this is a finding.
Fix: F-102843r1_fix
Configure the VPN Gateway to electronically verify Personal Identity Verification (PIV) credentials.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- SRG-NET-000343-VPN-001370
- Vuln IDs
-
- V-97177
- Rule IDs
-
- SV-106315r1_rule
Checks: C-96015r1_chk
Verity the VPN Gateway authenticates all network-connected endpoint devices before establishing a connection. If the VPN Gateway does not authenticate all network-connected endpoint devices before establishing a connection, this is a finding.
Fix: F-102859r1_fix
Configure the VPN Gateway to authenticate all network-connected endpoint devices before establishing a connection.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000352-VPN-001460
- Vuln IDs
-
- V-97179
- Rule IDs
-
- SV-106317r1_rule
Checks: C-96017r1_chk
Verify the VPN Gateway uses an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network. If the VPN Gateway does not use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network, this is a finding.
Fix: F-102861r1_fix
Configure the VPN Gateway to use an approved Commercial Solution for Classified (CSfC) when transporting classified traffic across an unclassified network.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-002397
- Version
- SRG-NET-000369-VPN-001620
- Vuln IDs
-
- V-97181
- Rule IDs
-
- SV-106319r1_rule
Checks: C-96019r1_chk
Verify the VPN Gateway disables split-tunneling for remote clients VPNs. If the VPN Gateway does not disable split-tunneling for remote clients VPNs, this is a finding.
Fix: F-102863r1_fix
Configure the VPN Gateway to disable split-tunneling for remote clients VPNs.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VPN-001640
- Vuln IDs
-
- V-97183
- Rule IDs
-
- SV-106321r1_rule
Checks: C-96021r1_chk
Verify the IPsec VPN Gateway specifies Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation. If the IPsec VPN Gateway does not specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation, this is a finding.
Fix: F-102865r1_fix
Configure the IPsec VPN Gateway to specify Perfect Forward Secrecy (PFS) during Internet Key Exchange (IKE) negotiation.
- RMF Control
- SC-8
- Severity
- H
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VPN-001650
- Vuln IDs
-
- V-97185
- Rule IDs
-
- SV-106323r1_rule
Checks: C-96023r1_chk
Verify the VPN Gateway and the remote access client are configured to protect the confidentiality and integrity of transmitted information. If VPN Gateway and Client does not protect the confidentiality and integrity of transmitted information, this is a finding.
Fix: F-102867r1_fix
Configure the VPN Gateway and the remote access client to protect the confidentiality and integrity of transmitted information.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002423
- Version
- SRG-NET-000375-VPN-001690
- Vuln IDs
-
- V-97187
- Rule IDs
-
- SV-106325r1_rule
Checks: C-96025r1_chk
Verify the IPsec VPN Gateway uses Encapsulating Security Payload (ESP) in tunnel mode for establishing secured paths to transport traffic between the organizations sites or between a gateway and remote end-stations. If the IPsec VPN Gateway must use Encapsulating Security Payload (ESP) in tunnel mode for establishing secured paths to transport traffic between the organizations sites or between a gateway and remote end-stations, this is a finding.
Fix: F-102869r1_fix
Configure the IPsec VPN Gateway to use Encapsulating Security Payload (ESP) in tunnel mode for establishing secured paths to transport traffic between the organizations sites or between a gateway and remote end-stations.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- SRG-NET-000400-VPN-001940
- Vuln IDs
-
- V-97189
- Rule IDs
-
- SV-106327r1_rule
Checks: C-96027r1_chk
For accounts using password authentication, verify the VPN Gateway uses FIPS-validated SHA-1 or later protocol to protect the integrity of the password authentication process. For accounts using password authentication, if the VPN Gateway does not use FIPS-validated SHA-1 or later protocol to protect the integrity of the password authentication process, this is a finding.
Fix: F-102871r1_fix
For accounts using password authentication, configure the VPN Gateway to use FIPS-validated SHA-1 or later protocol to protect the integrity of the password authentication process.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- SRG-NET-000492-VPN-001980
- Vuln IDs
-
- V-97191
- Rule IDs
-
- SV-106329r1_rule
Checks: C-96029r1_chk
Verify the VPN Gateway generates log records when successful and/or unsuccessful VPN connection attempts occur. If the VPN Gateway does not generate log records when successful and/or unsuccessful VPN connection attempts occur, this is a finding.
Fix: F-102873r1_fix
Configure the VPN Gateway to generate log records when successful and/or unsuccessful VPN connection attempts occur.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VPN-002160
- Vuln IDs
-
- V-97193
- Rule IDs
-
- SV-106331r1_rule
Checks: C-96031r1_chk
Verify the VPN Gateway uses a FIPS-validated cryptographic module to generate cryptographic hashes. If the VPN Gateway does not use a FIPS-validated cryptographic module to generate cryptographic hashes, this is a finding.
Fix: F-102875r1_fix
Configure the VPN Gateway to use a FIPS-validated cryptographic module to generate cryptographic hashes.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VPN-002170
- Vuln IDs
-
- V-97195
- Rule IDs
-
- SV-106333r1_rule
Checks: C-96033r1_chk
Verify the VPN Gateway uses a FIPS-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality. If the VPN Gateway does not use a FIPS-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality, this is a finding.
Fix: F-102877r1_fix
Configure the VPN Gateway to use a FIPS-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VPN-002180
- Vuln IDs
-
- V-97197
- Rule IDs
-
- SV-106335r1_rule
Checks: C-96035r1_chk
Verify the IPsec VPN Gateway IKE uses a NIST FIPS-validated cryptography to implement encryption services for unclassified VPN traffic. If the IPsec VPN Gateway IKE does not use NIST FIPS-validated cryptography to implement encryption services for unclassified VPN traffic, this is a finding.
Fix: F-102879r1_fix
Configure the IPsec VPN Gateway IKE to use NIST FIPS-validated cryptography to implement encryption services for unclassified VPN traffic.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VPN-002220
- Vuln IDs
-
- V-97199
- Rule IDs
-
- SV-106337r1_rule
Checks: C-96037r1_chk
Verify the IKE protocol is specified for all IPsec VPNs. If the IKE protocol is not specified as an option on all VPN gateways, this is a finding.
Fix: F-102881r1_fix
Configure the IPsec VPN Gateway to use IKE and IPsec VPN SAs.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VPN-002230
- Vuln IDs
-
- V-97201
- Rule IDs
-
- SV-106339r1_rule
Checks: C-96039r1_chk
Verify the VPN Gateway does not accept certificates that have been revoked when using PKI for authentication. If the VPN Gateway accepts certificates that have been revoked when using PKI for authentication, this is a finding.
Fix: F-102883r1_fix
Configure the VPN Gateway to not accept certificates that have been revoked when using PKI for authentication.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002363
- Version
- SRG-NET-000518-VPN-002280
- Vuln IDs
-
- V-97203
- Rule IDs
-
- SV-106341r1_rule
Checks: C-96041r1_chk
Verify the VPN Client logout function is configured to terminate the session on/with the VPN Gateway. If the VPN Client logout function does not terminate the session on/with the VPN Gateway, this is a finding.
Fix: F-102885r1_fix
Configure the VPN Client logout log out function must be configured to terminate the session on/with the VPN Gateway.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002364
- Version
- SRG-NET-000519-VPN-002290
- Vuln IDs
-
- V-97205
- Rule IDs
-
- SV-106343r1_rule
Checks: C-96043r1_chk
Verify the VPN Client displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions. If the VPN Client does not display an explicit logout message to users indicating the reliable termination of authenticated communications sessions, this is a finding.
Fix: F-102887r1_fix
Configure the VPN Client to display an explicit logout message to users indicating the reliable termination of authenticated communications sessions.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000196
- Version
- SRG-NET-000522-VPN-002320
- Vuln IDs
-
- V-97207
- Rule IDs
-
- SV-106345r1_rule
Checks: C-96045r1_chk
Verify the VPN Gateway stores only cryptographic representations of the PSK. If the VPN Gateway does not store only cryptographic representations of the PSK, this is a finding.
Fix: F-102889r1_fix
Configure the VPN Gateway to store only cryptographic representations of the PSK.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- SRG-NET-000525-VPN-002330
- Vuln IDs
-
- V-97209
- Rule IDs
-
- SV-106347r1_rule
Checks: C-96047r1_chk
Verify all Internet Key Exchange (IKE) proposals are set to use the AES encryption algorithm. View the value of the encryption algorithm for each defined proposal. If the value of the encryption algorithm for any IPsec proposal is not set to use an AES algorithm, this is a finding.
Fix: F-102891r1_fix
Configure the IPsec Gateway to use AES for the IPsec proposal. The following example commands configure the IPsec (phase 2) proposals. The option may also be configured to use the aes-128-cbc, aes-192-cbc, or aes-256-cbc algorithms.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- SRG-NET-000530-VPN-002340
- Vuln IDs
-
- V-97211
- Rule IDs
-
- SV-106349r1_rule
Checks: C-96049r1_chk
Verify the TLS VPN Gateway that supports Government-only services prohibits client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0. If the TLS VPN Gateway that supports Government-only services does not prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0, this is a finding.
Fix: F-102893r1_fix
Configure the TLS VPN Gateway that supports Government-only services to prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- SRG-NET-000540-VPN-002350
- Vuln IDs
-
- V-97213
- Rule IDs
-
- SV-106351r1_rule
Checks: C-96051r1_chk
Verify the TLS VPN Gateway that supports citizen- or business-facing network devices prohibits client negotiation to SSL 2.0 or SSL 3.0. If the TLS VPN Gateway that supports citizen- or business-facing network devices does not prohibit client negotiation to SSL 2.0 or SSL 3.0, this is a finding.
Fix: F-102895r1_fix
Configure the TLS VPN Gateway that supports citizen- or business-facing network devices to prohibit client negotiation to SSL 2.0 or SSL 3.0.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- SRG-NET-000550-VPN-002360
- Vuln IDs
-
- V-97215
- Rule IDs
-
- SV-106353r1_rule
Checks: C-96053r1_chk
Verify the VPN Gateway that provides a Simple Network Management Protocol (SNMP) Network Management System (NMS) is configured to use SNMPv3 to use FIPS-validated AES cipher block algorithm. If the VPN Gateway that provides a Simple Network Management Protocol (SNMP) Network Management System (NMS) does not configure SNMPv3 to use FIPS-validated AES cipher block algorithm, this is a finding.
Fix: F-102897r1_fix
The VPN Gateway that provides a Simple Network Management Protocol (SNMP) Network Management System (NMS) must configure SNMPv3 to use FIPS-validated AES cipher block algorithm.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- SRG-NET-000565-VPN-002390
- Vuln IDs
-
- V-97217
- Rule IDs
-
- SV-106355r1_rule
Checks: C-96055r1_chk
Verify the VPN Gateway uses an approved High Assurance Commercial Solution for Classified (CSfC) cryptographic algorithm for remote access to a classified network. If the VPN Gateway does not use an approved High Assurance Commercial Solution for Classified (CSfC) cryptographic algorithm for remote access to a classified network, this is a finding.
Fix: F-102899r1_fix
Configure the VPN Gateway to use an approved High Assurance Commercial Solution for Classified (CSfC) cryptographic algorithm for remote access to a classified network.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- SRG-NET-000565-VPN-002400
- Vuln IDs
-
- V-97219
- Rule IDs
-
- SV-106357r1_rule
Checks: C-96057r1_chk
Verify the IPsec VPN Gateway Internet Key Exchange (IKE) uses cryptography that is compliant with Suite B parameters when transporting classified traffic across an unclassified network. If the IPsec VPN Gateway Internet Key Exchange (IKE) does not use cryptography that is compliant with Suite B parameters when transporting classified traffic across an unclassified network, this is a finding.
Fix: F-102901r1_fix
Configure the IPsec VPN Gateway Internet Key Exchange (IKE) to use cryptography that is compliant with Suite B parameters when transporting classified traffic across an unclassified network.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- SRG-NET-000580-VPN-002410
- Vuln IDs
-
- V-97221
- Rule IDs
-
- SV-106359r1_rule
Checks: C-96059r1_chk
Verify the VPN Gateway validates TLS certificates by performing RFC 5280-compliant certification path validation. If the VPN Gateway does not validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation, this is a finding.
Fix: F-102903r1_fix
Configure the VPN Gateway to validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SRG-NET-000585-VPN-002420
- Vuln IDs
-
- V-97223
- Rule IDs
-
- SV-106361r1_rule
Checks: C-96061r1_chk
Verify the VPN Gateway uses FIPS-validated SHA-2 or higher hash function for digital signature generation and verification (non-legacy use). If the VPN Gateway does not use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification (non-legacy use), this is a finding.
Fix: F-102905r1_fix
Configure the VPN Gateway to use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification (non-legacy use).
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- SRG-NET-000075-VPN-000260
- Vuln IDs
-
- V-97225
- Rule IDs
-
- SV-106363r1_rule
Checks: C-96063r1_chk
If L2TP communications protocol is not used, this is not applicable. Verify L2TPv3 sessions are configured to authenticate the traffic before transit. L2TPv3 sessions must be authenticated prior to transporting traffic. If L2TPv3 sessions do not require authentication, this is a finding.
Fix: F-102907r1_fix
If the site-to-site VPN implementation uses L2TPv3, configure L2TPv3 sessions to authenticate the traffic before transit.