The IPsec VPN Gateway must use IKEv2 for IPsec VPN security associations.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-207205
SRG-NET-000132-VPN-000460
SV-207205r608988_rule
Medium
Description
In order to prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embedding of data types within data types); organizations must disable or restrict unused or unnecessary physical and logical ports/protocols on information systems.
Use of IKEv2 leverages DoS protections because of improved bandwidth management and leverages more secure encryption algorithms.