STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured to use multifactor authentication (MFA) for interactive logins.

DISA Rule

SV-266085r1113746_rule

Vulnerability Number

V-266085

Group Title

SRG-APP-000149-NDM-000247

Rule Version

F5BI-DM-300046

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Click "Change".
5. Select RADIUS, or TACACS+ from the "Remote" options and fill out the configuration depending on the chosen option.
6. Fill out all other fields as appropriate for the environment.
7. Click "Finished".

Note: This method has been verified with the vendor and DISA for use in DOD. Other methods are not recommended/have not been tested to determine if DOD requirements have been met or if additional licenses and AO approval are required.

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify "User Directory" is configured to use RADIUS or TACACS+.

From the BIG-IP console, type the following command(s):

tmsh list auth source

Verify "User Directory" is configured to use RADIUS or TACACS+.

If the BIG-IP appliance is not configured to use DOD PKI with RADIUS or TACACS+ for interactive logins, this is a finding.

Vulnerability Number

V-266085

Documentable

False

Rule Version

F5BI-DM-300046

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify "User Directory" is configured to use RADIUS or TACACS+.

From the BIG-IP console, type the following command(s):

tmsh list auth source

Verify "User Directory" is configured to use RADIUS or TACACS+.

If the BIG-IP appliance is not configured to use DOD PKI with RADIUS or TACACS+ for interactive logins, this is a finding.

Check Content Reference

M

Target Key

5639