The TLS VPN Gateway must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during transmission for remote access connections.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-207190
SRG-NET-000062-VPN-000200
SV-207190r803417_rule
High
Description
Using older unauthorized versions or incorrectly configuring protocol negotiation makes the gateway vulnerable to known and unknown attacks that exploit vulnerabilities in this protocol.
NIST SP 800-52 Rev2 provides guidance for client negotiation on either DoD-only or public-facing servers.