STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing intermediary services for remote access must use FIPS-validated cryptographic algorithms, including TLS 1.2 at a minimum.

DISA Rule

SV-266139r1024837_rule

Vulnerability Number

V-266139

Group Title

SRG-NET-000062-ALG-000011

Rule Version

F5BI-AP-300003

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Client SSL Profile
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. SSL.
4. Client.
5. Click on the name of the SSL Profile.
6. Change "Configuration" to "Advanced".
7. Configure "Ciphers" to use NIST FIPS-validated ciphers.
8. Click "Update".
9. Repeat for other SSL Profiles in use.

Virtual Server
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the virtual server.
5. Configure "SSL Profile (Client)" to use a NIST FIPS-validated SSL Profile.
6. Click "Update".
7. Repeat for other virtual servers.

Check Contents

If the BIG-IP appliance does not provide intermediary services for remote access (e.g., web content filter, TLS, and webmail), TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.

Client SSL Profile
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. SSL.
4. Client.
5. Click on the name of the SSL Profile.
6. Change "Configuration" to "Advanced".
7. Verify "Ciphers" is configured to use NIST FIPS-validated ciphers.
8. Repeat for other SSL Profiles in use.

Virtual Server
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the virtual server.
5. Verify that the "SSL Profile (Client)" is using a NIST FIPS-validated SSL Profile.
6. Repeat these steps to review all other virtual servers.

If the BIG-IP appliance is not configured to use TLS 1.2 or higher, this is a finding.

Vulnerability Number

V-266139

Documentable

False

Rule Version

F5BI-AP-300003

Severity Override Guidance

If the BIG-IP appliance does not provide intermediary services for remote access (e.g., web content filter, TLS, and webmail), TLS, or application protocols that use TLS (e.g., DNSSEC or HTTPS), this is not applicable.

Client SSL Profile
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. SSL.
4. Client.
5. Click on the name of the SSL Profile.
6. Change "Configuration" to "Advanced".
7. Verify "Ciphers" is configured to use NIST FIPS-validated ciphers.
8. Repeat for other SSL Profiles in use.

Virtual Server
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the virtual server.
5. Verify that the "SSL Profile (Client)" is using a NIST FIPS-validated SSL Profile.
6. Repeat these steps to review all other virtual servers.

If the BIG-IP appliance is not configured to use TLS 1.2 or higher, this is a finding.

Check Content Reference

M

Target Key

5640