STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

DISA Rule

SV-266084r1043177_rule

Vulnerability Number

V-266084

Group Title

SRG-APP-000142-NDM-000245

Rule Version

F5BI-DM-300045

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Check the PPSM CAL and the site's System Security Plan/documentation for a list of prohibited ports, protocols, and services.

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. For any virtual server(s) listening on all unnecessary and/or nonsecure functions, ports, protocols, and/or services, check the box next to the virtual server and click "Delete".
4. Click "Delete" again.

Check Contents

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Verify the list of virtual servers are not configured to listen on unnecessary and/or nonsecure functions, ports, protocols, and/or services.

If the BIG-IP appliance is configured to listen or run unnecessary and/or nonsecure functions, ports, protocols, and/or services, this is a finding.

Vulnerability Number

V-266084

Documentable

False

Rule Version

F5BI-DM-300045

Severity Override Guidance

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Verify the list of virtual servers are not configured to listen on unnecessary and/or nonsecure functions, ports, protocols, and/or services.

If the BIG-IP appliance is configured to listen or run unnecessary and/or nonsecure functions, ports, protocols, and/or services, this is a finding.

Check Content Reference

M

Target Key

5639