Information
Without strong cryptographic integrity protections, information can be altered by unauthorized users without detection.
SHA-1 is considered a compromised hashing standard and is being phased out of use by industry and government standards. DOD systems must not be configured to use SHA-1 for integrity of remote access sessions.
The remote access VPN provides access to DOD nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganization-controlled network.
Satisfies: SRG-NET-000063-VPN-000220, SRG-NET-000074-VPN-000250, SRG-NET-000168-VPN-000600, SRG-NET-000230-VPN-000780
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Configure AOS with the following commands:
configure terminal
crypto isakmp policy <priority>
hash sha2-384-192
exit
write memory
Item Details
Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
References: 800-53|AC-17(2), 800-53|IA-7, 800-53|SC-23, CAT|II, CCI|CCI-000068, CCI|CCI-000803, CCI|CCI-001184, CCI|CCI-001453, Rule-ID|SV-266983r1040715_rule, STIG-ID|ARBA-VN-000220, Vuln-ID|V-266983
Control ID: 0862ea04977be6c45eb52564ad4bc672e5b96ca0e0ecd340bcd3a19908b00102