cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
684
Views
0
Helpful
2
Replies

Set AES for ISAKMP?

K-Grev
Level 1
Level 1

Hi,

 

Help me out. Im just scratching my head on this one even though I've been here before.

I'm STIG-ing an ASA.

 

Where on ASDM can I configure all ISAKMP policies to use AES for IKE encryption?

Or what command can I use to check that my configured set have the appropriate AES level?

 

Thanks

 

(referenced STIG Rule)

https://www.stigviewer.com/stig/ipsec_vpn_gateway/2018-11-27/finding/V-30952

1 Accepted Solution

Accepted Solutions

Hi @K-Grev 

I don't know where the location is on ASDM but use the command show vpn-sessiondb ratio encryption on the CLI, which will tell you the number of tunnels are using which algorithms. From the CLI you can check your ISAKMP/IKEv1 policies using the command show run crypto isakmp or show run crypto ikev1, if any policies are using DES/3DES amend accordingly. Provide the output for review if you need further help.

 

HTH

View solution in original post

2 Replies 2

Hi @K-Grev 

I don't know where the location is on ASDM but use the command show vpn-sessiondb ratio encryption on the CLI, which will tell you the number of tunnels are using which algorithms. From the CLI you can check your ISAKMP/IKEv1 policies using the command show run crypto isakmp or show run crypto ikev1, if any policies are using DES/3DES amend accordingly. Provide the output for review if you need further help.

 

HTH

Thanks Rob, that helped a lot.

Also on ASDM i found that Config>site-to-site VPN> Advanced > IKE Policies helped.