STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured to use at least two authentication servers to authenticate administrative users.

DISA Rule

SV-266079r1024884_rule

Vulnerability Number

V-266079

Group Title

SRG-APP-000516-NDM-000336

Rule Version

F5BI-DM-300040

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
RADIUS:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - RADIUS", click "Change" at the bottom.
5. Configure values for Primary and Secondary servers.
Note: To view Primary and Secondary Hosts, the "Server Configuration" must be set to "Primary & Secondary".
6. Click "Finished".

TACACS+
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - TACACS+", click "Change" at the bottom
5. Add multiple IP Addresses to the "Servers" field.
6. Set "Authentication" to "Authenticate to each server until success".
7. Click "Finished".

Check Contents

From the BIG-IP GUI:
RADIUS:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - RADIUS", verify different Primary and Secondary Hosts exist in the configuration.
Note: To view Primary and Secondary Hosts, the "Server Configuration" must be set to "Primary & Secondary".

TACACS+
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - TACACS+", verify multiple servers exist in the configuration.
5. Verify "Authentication" is set to "Authenticate to each server until success".

If the BIG-IP appliance is not configured to use at least two authentication servers to authenticate administrative users, this is a finding.

Vulnerability Number

V-266079

Documentable

False

Rule Version

F5BI-DM-300040

Severity Override Guidance

From the BIG-IP GUI:
RADIUS:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - RADIUS", verify different Primary and Secondary Hosts exist in the configuration.
Note: To view Primary and Secondary Hosts, the "Server Configuration" must be set to "Primary & Secondary".

TACACS+
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - TACACS+", verify multiple servers exist in the configuration.
5. Verify "Authentication" is set to "Authenticate to each server until success".

If the BIG-IP appliance is not configured to use at least two authentication servers to authenticate administrative users, this is a finding.

Check Content Reference

M

Target Key

5639