STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Sep 2024:

The F5 BIG-IP DNS server implementation must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks.

DISA Rule

SV-265991r1024501_rule

Vulnerability Number

V-265991

Group Title

SRG-APP-000247-DNS-000036

Rule Version

F5BI-DN-300039

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This requires the AFM license or can be implemented using another firewall's ACL.

From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand DNS and do the following for each:
a. Check the box at the top of the list of signatures to select all.
b. Set "Set State" to "Mitigate".
c. Click "Commit Changes to System".

Note: Sites must operationally test, adjust thresholds, or initially use learning mode prior to turning on mitigation to prevent operational impacts, particularly in implementations with large traffic volumes.

Check Contents

From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand DNS and verify the "State" is set to "Mitigate" for all signatures.

If the BIG-IP appliance is not configured to restrict the ability of individuals to use the DNS server to launch DoS attacks against other information systems, this is a finding.

Vulnerability Number

V-265991

Documentable

False

Rule Version

F5BI-DN-300039

Severity Override Guidance

From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand DNS and verify the "State" is set to "Mitigate" for all signatures.

If the BIG-IP appliance is not configured to restrict the ability of individuals to use the DNS server to launch DoS attacks against other information systems, this is a finding.

Check Content Reference

M

Target Key

5638