STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance that provides intermediary services for SMTP must inspect inbound and outbound SMTP and Extended SMTP communications traffic for protocol compliance and protocol anomalies.

DISA Rule

SV-266147r1024374_rule

Vulnerability Number

V-266147

Group Title

SRG-NET-000512-ALG-000064

Rule Version

F5BI-AP-300041

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

SMTP Profile:
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. Services.
4. SMTP.
5. Click the name of the SMTP profile.
6. Check "Protocol Security".
7. Click "Update".

SMTP Virtual Server:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the SMTP virtual server.
5. Select the SMTP profile from the "SMTP Profile" drop-down list.
6. Click "Update".

Refer to vendor documentation for more information.

Check Contents

If the BIG-IP appliance does not provide intermediary/proxy services for SMTP communications traffic, this is not applicable.

SMTP Profile:
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. Services.
4. SMTP.
5. Click the name of the SMTP profile.
6. Verify "Protocol Security" is checked.

SMTP Virtual Server:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the SMTP virtual server.
5. Verify the SMTP profile is selected in the "SMTP Profile" drop-down list.

If the BIG-IP appliance is not configured to inspect inbound and outbound SMTP and Extended SMTP communications traffic for protocol compliance and protocol anomalies, this is a finding.

Vulnerability Number

V-266147

Documentable

False

Rule Version

F5BI-AP-300041

Severity Override Guidance

If the BIG-IP appliance does not provide intermediary/proxy services for SMTP communications traffic, this is not applicable.

SMTP Profile:
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. Services.
4. SMTP.
5. Click the name of the SMTP profile.
6. Verify "Protocol Security" is checked.

SMTP Virtual Server:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the SMTP virtual server.
5. Verify the SMTP profile is selected in the "SMTP Profile" drop-down list.

If the BIG-IP appliance is not configured to inspect inbound and outbound SMTP and Extended SMTP communications traffic for protocol compliance and protocol anomalies, this is a finding.

Check Content Reference

M

Target Key

5640