SV-266149r1024844_rule
V-266149
SRG-NET-000512-ALG-000066
F5BI-AP-300043
CAT II
10
Application Security Policy:
From the BIG-IP GUI:
1. Security.
2. Application Security.
3. Policy Building.
4. Learning and Blocking Settings.
5. Select the correct policy from the drop-down in the upper left.
6. Expand "HTTP protocol compliance failed".
7. Select the proper inspection criteria.
8. Click "Save".
9. Click "Apply Policy".
HTTP Virtual Server:
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the HTTP virtual server.
5. Security >> Policies tab.
6. Set "Application Security Policy" to "Enabled".
7. Select the correct policy from the drop-down.
8. Click "Update".
Refer to vendor documentation for more information.
If the BIG-IP appliance does not provide intermediary/proxy services for HTTP communications traffic, this is not applicable.
Application Security Policy:
From the BIG-IP GUI:
1. Security.
2. Application Security.
3. Policy Building.
4. Learning and Blocking Settings.
5. Verify the correct policy is selected from the drop-down in the upper left.
6. Expand "HTTP protocol compliance failed".
7. Verify the proper inspection criteria are selected.
HTTP Virtual Server:
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the HTTP Virtual Server.
5. Security >> Policies tab.
6. Verify the correct policy is selected for "Application Security Policy".
If the BIG-IP appliance is not configured to inspect inbound and outbound HTTP communications traffic for protocol compliance and protocol anomalies, this is a finding.
V-266149
False
F5BI-AP-300043
If the BIG-IP appliance does not provide intermediary/proxy services for HTTP communications traffic, this is not applicable.
Application Security Policy:
From the BIG-IP GUI:
1. Security.
2. Application Security.
3. Policy Building.
4. Learning and Blocking Settings.
5. Verify the correct policy is selected from the drop-down in the upper left.
6. Expand "HTTP protocol compliance failed".
7. Verify the proper inspection criteria are selected.
HTTP Virtual Server:
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the HTTP Virtual Server.
5. Security >> Policies tab.
6. Verify the correct policy is selected for "Application Security Policy".
If the BIG-IP appliance is not configured to inspect inbound and outbound HTTP communications traffic for protocol compliance and protocol anomalies, this is a finding.
M
5640