SV-266157r1024386_rule
V-266157
SRG-NET-000362-ALG-000155
F5BI-AP-300061
CAT II
10
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand "Network".
5. Click "Configure settings".
6. Set "Dynamic Signature Detection" to "Enabled".
7. If applicable, expand "DNS".
8. Click "Configure settings".
9. Set "Dynamic Signature Detection" to "Enabled".
10. Click "Commit Changes to System".
If the BIG-IP appliance does not perform content filtering as part of the traffic management functions, this is not applicable.
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand "Network" and verify "Dynamic Signatures" are enabled.
5. If applicable, expand "DNS" and verify "Dynamic Signatures" are enabled.
If the BIG-IP appliance is not configured to protect against or limit the effects of known and unknown types of DoS attacks by employing pattern recognition pre-processors, this is a finding.
V-266157
False
F5BI-AP-300061
If the BIG-IP appliance does not perform content filtering as part of the traffic management functions, this is not applicable.
From the BIG-IP GUI:
1. Security.
2. DoS Protection.
3. Device Protection.
4. Expand "Network" and verify "Dynamic Signatures" are enabled.
5. If applicable, expand "DNS" and verify "Dynamic Signatures" are enabled.
If the BIG-IP appliance is not configured to protect against or limit the effects of known and unknown types of DoS attacks by employing pattern recognition pre-processors, this is a finding.
M
5640