STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing user access control intermediary services must limit the "Max Sessions Per User" to one or an organization-defined number for each access profile.

DISA Rule

SV-266137r1212026_rule

Vulnerability Number

V-266137

Group Title

SRG-NET-000053-ALG-000001

Rule Version

F5BI-AP-300001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the Name of the Access profile.
5. Under "Settings", set "Max Sessions per User" to "1" or to an organization-defined number.
6. Update.

Check Contents

If the BIG-IP appliance does not provide user access control intermediary services, this is not applicable.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the Name of the Access profile.
5. Under "Settings", verify "Max Sessions per User" is set to "1" or to an organization-defined number.

If the BIG-IP appliance is not configured to limit the number of concurrent sessions for user accounts to 1 or to an organization-defined number, this is a finding.

Vulnerability Number

V-266137

Documentable

False

Rule Version

F5BI-AP-300001

Severity Override Guidance

If the BIG-IP appliance does not provide user access control intermediary services, this is not applicable.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the Name of the Access profile.
5. Under "Settings", verify "Max Sessions per User" is set to "1" or to an organization-defined number.

If the BIG-IP appliance is not configured to limit the number of concurrent sessions for user accounts to 1 or to an organization-defined number, this is a finding.

Check Content Reference

M

Target Key

5640