STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing user authentication intermediary services must uniquely identify and authenticate users using redundant authentication servers and multifactor authentication (MFA).

DISA Rule

SV-266152r1024845_rule

Vulnerability Number

V-266152

Group Title

SRG-NET-000138-ALG-000063

Rule Version

F5BI-AP-300047

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles (Per-Session Policies).
4. Click "Edit" for the Access Profile being used.
5. Configure the Access Profile to use a separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication.

Note: To create an authentication object in the VPE, it must first be created in APM under Access >> Authentication. Once it has been created, add it to the Access Policy VPE by clicking the "+", selecting the "Authentication" tab, and select the appropriate type of authentication.

Check Contents

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles (Per-Session Policies).
4. Click "Edit" for the Access Profile being used.
5. Verify the Access Profile uses an authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication.

If the BIG-IP appliance is not configured to use a separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication, this is a finding.

Vulnerability Number

V-266152

Documentable

False

Rule Version

F5BI-AP-300047

Severity Override Guidance

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles (Per-Session Policies).
4. Click "Edit" for the Access Profile being used.
5. Verify the Access Profile uses an authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication.

If the BIG-IP appliance is not configured to use a separate authentication server (e.g., LDAP, RADIUS, TACACS+) to perform user authentication, this is a finding.

Check Content Reference

M

Target Key

5640