SV-266079r1024884_rule
V-266079
SRG-APP-000516-NDM-000336
F5BI-DM-300040
CAT I
10
From the BIG-IP GUI:
RADIUS:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - RADIUS", click "Change" at the bottom.
5. Configure values for Primary and Secondary servers.
Note: To view Primary and Secondary Hosts, the "Server Configuration" must be set to "Primary & Secondary".
6. Click "Finished".
TACACS+
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - TACACS+", click "Change" at the bottom
5. Add multiple IP Addresses to the "Servers" field.
6. Set "Authentication" to "Authenticate to each server until success".
7. Click "Finished".
From the BIG-IP GUI:
RADIUS:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - RADIUS", verify different Primary and Secondary Hosts exist in the configuration.
Note: To view Primary and Secondary Hosts, the "Server Configuration" must be set to "Primary & Secondary".
TACACS+
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - TACACS+", verify multiple servers exist in the configuration.
5. Verify "Authentication" is set to "Authenticate to each server until success".
If the BIG-IP appliance is not configured to use at least two authentication servers to authenticate administrative users, this is a finding.
V-266079
False
F5BI-DM-300040
From the BIG-IP GUI:
RADIUS:
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - RADIUS", verify different Primary and Secondary Hosts exist in the configuration.
Note: To view Primary and Secondary Hosts, the "Server Configuration" must be set to "Primary & Secondary".
TACACS+
1. System.
2. Users.
3. Authentication.
4. If "User Directory" is configured for "Remote - TACACS+", verify multiple servers exist in the configuration.
5. Verify "Authentication" is set to "Authenticate to each server until success".
If the BIG-IP appliance is not configured to use at least two authentication servers to authenticate administrative users, this is a finding.
M
5639