STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must be configured to prohibit or restrict the use of unnecessary or prohibited functions, ports, protocols, and/or services, including those defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-266150r1024377_rule

Vulnerability Number

V-266150

Group Title

SRG-NET-000132-ALG-000087

Rule Version

F5BI-AP-300045

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Check the PPSM CAL and the site's System Security Plan/documentation for a list of prohibited ports, protocols, and services.

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. For any virtual server(s) listening on all unnecessary and/or nonsecure functions, ports, protocols, and/or services, check the box next to the virtual server and click "Delete".
4. Click "Delete" again.

Check Contents

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Verify the list of virtual servers are not configured to listen on unnecessary and/or nonsecure functions, ports, protocols, and/or services.

If any services are running that must not be, this is a finding.

Vulnerability Number

V-266150

Documentable

False

Rule Version

F5BI-AP-300045

Severity Override Guidance

From the BIG-IP GUI:
1. Local Traffic.
2. Virtual Servers.
3. Verify the list of virtual servers are not configured to listen on unnecessary and/or nonsecure functions, ports, protocols, and/or services.

If any services are running that must not be, this is a finding.

Check Content Reference

M

Target Key

5640