JUSX-VN-000016 - The Juniper SRX Services Gateway VPN must use IKEv2 for IPsec VPN security associations.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Use of IKEv2 leverages DoS protections because of improved bandwidth management and leverages more secure encryption algorithms.

Solution

For site-to-site VPNs, configure the Juniper SRX to use IKEv2 only.

[edit]
set security ike gateway <VPN-GATEWAY> address <GW-IP-ADDRESS>
set security ike gateway <VPN-GATEWAY> version v2-only

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_SRX_SG_Y22M10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000382, Rule-ID|SV-214683r385486_rule, STIG-ID|JUSX-VN-000016, STIG-Legacy|SV-81151, STIG-Legacy|V-66661, Vuln-ID|V-214683

Plugin: Juniper

Control ID: d821b8aa866b8666d7f1413346e719f3d45adc9c8e08c971ee98223afc201e16