Configure IPsec Tunnel Parameters - cipher-suite

Information

You can change the encryption on the IPsec tunnel to the AES-256 cipher in CBC (cipher block chaining mode, with HMAC using either SHA-1 or SHA-2 keyed-hash message authentication or to null with HMAC using either SHA-1 or SHA-2 keyed-hash message authentication, to not encrypt the IPsec tunnel used for IKE key exchange traffic.

See https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/vedge-20-x/security-book/config-sec-param.html for more information.

Solution

vEdge(config-interface-ipsecnumber)# ipsec
vEdge(config-ipsec)# cipher-suite (aes256-cbc-sha1 | aes256-gcm | null-sha1)

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4

Plugin: Cisco_Viptela

Control ID: 355480c930dcd45563e0341c8cff93c80a2a7c305f9319905bccec9e3d7ed74f