SV-266068r1029557_rule
V-266068
SRG-APP-000343-NDM-000289
F5BI-DM-300012
CAT II
10
From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Options.
5. Under "Local Traffic Logging":
a. MCP: Notice.
b. SSL: Informational.
c. Traffic Management OS: Informational.
6. Under "Audit Logging":
a. MCP: Enable.
7. Update.
From the BIG-IP console, type the following commands:
tmsh modify sys daemon-log-settings tmm os-log-level informational
tmsh modify sys daemon-log-settings tmm ssl-log-level informational
tmsh modify sys daemon-log-settings mcpd audit enabled
tmsh modify sys daemon-log-settings mcpd log-level notice
tmsh modify sys db log.ssl.level value informational
tmsh save sys config
From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Options.
5. Under Local Traffic Logging:
a. MCP: Notice.
b. SSL: Informational.
c. Traffic Management OS: Informational.
6. Under Audit Logging:
a. MCP: Enable.
From the BIG-IP console, type the following commands:
tmsh list sys daemon-log-settings tmm os-log-level
Note: This command must return a value of "informational".
tmsh list sys daemon-log-settings tmm ssl-log-level
Note: This must return a value of "informational":
tmsh list sys daemon-log-settings mcpd audit
Note: This must return a value of "enabled".
tmsh list sys daemon-log-settings mcpd log-level
Note: This must return a value of "notice".
tmsh list sys db log.ssl.level value
Note: This must return a value of "informational".
If the BIG-IP appliance is not configured to audit the execution of privileged functions, this is a finding.
V-266068
False
F5BI-DM-300012
From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Options.
5. Under Local Traffic Logging:
a. MCP: Notice.
b. SSL: Informational.
c. Traffic Management OS: Informational.
6. Under Audit Logging:
a. MCP: Enable.
From the BIG-IP console, type the following commands:
tmsh list sys daemon-log-settings tmm os-log-level
Note: This command must return a value of "informational".
tmsh list sys daemon-log-settings tmm ssl-log-level
Note: This must return a value of "informational":
tmsh list sys daemon-log-settings mcpd audit
Note: This must return a value of "enabled".
tmsh list sys daemon-log-settings mcpd log-level
Note: This must return a value of "notice".
tmsh list sys db log.ssl.level value
Note: This must return a value of "informational".
If the BIG-IP appliance is not configured to audit the execution of privileged functions, this is a finding.
M
5639