STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must generate audit records and send records to redundant central syslog servers that are separate from the appliance.

DISA Rule

SV-266075r1024607_rule

Vulnerability Number

V-266075

Group Title

SRG-APP-000515-NDM-000325

Rule Version

F5BI-DM-300034

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure two or more central syslog servers.

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Remote Logging.
5. Add the IP address of a syslog server in the "Remote IP" field, modify the port if necessary, and click "Add".
6. Click "Update".

From the BIG-IP Console, issue the following commands:

tmsh modify sys syslog remote-servers add { <name> { host <ip address> remote-port <port> } }
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Remote Logging.

From the BIG-IP Console, issue the following command:

tmsh list sys syslog remote-servers

Note: This must return at least two remote IP addresses of syslog server.

If the BIG-IP appliance does not send audit records to one or more central syslog servers that are separate from the appliance, this is a finding.

Vulnerability Number

V-266075

Documentable

False

Rule Version

F5BI-DM-300034

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Logs.
3. Configuration.
4. Remote Logging.

From the BIG-IP Console, issue the following command:

tmsh list sys syslog remote-servers

Note: This must return at least two remote IP addresses of syslog server.

If the BIG-IP appliance does not send audit records to one or more central syslog servers that are separate from the appliance, this is a finding.

Check Content Reference

M

Target Key

5639