STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance that provides intermediary services for HTTP must inspect inbound and outbound HTTP traffic for protocol compliance and protocol anomalies.

DISA Rule

SV-266149r1024844_rule

Vulnerability Number

V-266149

Group Title

SRG-NET-000512-ALG-000066

Rule Version

F5BI-AP-300043

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Application Security Policy:
From the BIG-IP GUI:
1. Security.
2. Application Security.
3. Policy Building.
4. Learning and Blocking Settings.
5. Select the correct policy from the drop-down in the upper left.
6. Expand "HTTP protocol compliance failed".
7. Select the proper inspection criteria.
8. Click "Save".
9. Click "Apply Policy".

HTTP Virtual Server:
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the HTTP virtual server.
5. Security >> Policies tab.
6. Set "Application Security Policy" to "Enabled".
7. Select the correct policy from the drop-down.
8. Click "Update".

Refer to vendor documentation for more information.

Check Contents

If the BIG-IP appliance does not provide intermediary/proxy services for HTTP communications traffic, this is not applicable.

Application Security Policy:
From the BIG-IP GUI:
1. Security.
2. Application Security.
3. Policy Building.
4. Learning and Blocking Settings.
5. Verify the correct policy is selected from the drop-down in the upper left.
6. Expand "HTTP protocol compliance failed".
7. Verify the proper inspection criteria are selected.

HTTP Virtual Server:
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the HTTP Virtual Server.
5. Security >> Policies tab.
6. Verify the correct policy is selected for "Application Security Policy".

If the BIG-IP appliance is not configured to inspect inbound and outbound HTTP communications traffic for protocol compliance and protocol anomalies, this is a finding.

Vulnerability Number

V-266149

Documentable

False

Rule Version

F5BI-AP-300043

Severity Override Guidance

If the BIG-IP appliance does not provide intermediary/proxy services for HTTP communications traffic, this is not applicable.

Application Security Policy:
From the BIG-IP GUI:
1. Security.
2. Application Security.
3. Policy Building.
4. Learning and Blocking Settings.
5. Verify the correct policy is selected from the drop-down in the upper left.
6. Expand "HTTP protocol compliance failed".
7. Verify the proper inspection criteria are selected.

HTTP Virtual Server:
From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Virtual Server List.
4. Click the name of the HTTP Virtual Server.
5. Security >> Policies tab.
6. Verify the correct policy is selected for "Application Security Policy".

If the BIG-IP appliance is not configured to inspect inbound and outbound HTTP communications traffic for protocol compliance and protocol anomalies, this is a finding.

Check Content Reference

M

Target Key

5640