STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance that intermediary services for FTP must inspect inbound and outbound FTP communications traffic for protocol compliance and protocol anomalies.

DISA Rule

SV-266148r1138544_rule

Vulnerability Number

V-266148

Group Title

SRG-NET-000512-ALG-000065

Rule Version

F5BI-AP-300042

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

FTP Profile:
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. Services.
4. FTP.
5. Click the name of the FTP profile.
6. Check "Protocol Security".
7. Click "Update".

FTP Virtual Server:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the FTP virtual server.
5. Select the FTP profile from the "FTP Profile" drop-down list.
6. Click "Update".

Refer to vendor documentation for more information.

Check Contents

If the BIG-IP appliance does not provide intermediary/proxy services for FTP communications traffic, this is not applicable.

FTP Profile:
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. Services.
4. FTP.
5. Click the name of the FTP profile.
6. Verify "Protocol Security" is checked.

FTP Virtual Server:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the FTP virtual server.
5. Verify the FTP profile is selected in the "FTP Profile" drop-down list.

If the BIG-IP appliance is not configured to inspect inbound and outbound FTP communications traffic for protocol compliance and protocol anomalies, this is a finding.

Vulnerability Number

V-266148

Documentable

False

Rule Version

F5BI-AP-300042

Severity Override Guidance

If the BIG-IP appliance does not provide intermediary/proxy services for FTP communications traffic, this is not applicable.

FTP Profile:
From the BIG-IP GUI:
1. Local Traffic.
2. Profiles.
3. Services.
4. FTP.
5. Click the name of the FTP profile.
6. Verify "Protocol Security" is checked.

FTP Virtual Server:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the FTP virtual server.
5. Verify the FTP profile is selected in the "FTP Profile" drop-down list.

If the BIG-IP appliance is not configured to inspect inbound and outbound FTP communications traffic for protocol compliance and protocol anomalies, this is a finding.

Check Content Reference

M

Target Key

5640