STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing content filtering must automatically update malicious code protection mechanisms.

DISA Rule

SV-266159r1024388_rule

Vulnerability Number

V-266159

Group Title

SRG-NET-000251-ALG-000131

Rule Version

F5BI-AP-300065

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Note: Automatic signature updates can be configured, but depending on site connectivity this may not be possible. In this case, manual upload of updates is possible. The below covers automatic update configuration.

Automatic Update Check:
From the BIG-IP GUI:
1. System.
2. Software Management.
3. Update Check.
4. Set "Automatic Update Check" to "Enabled".
5. Click "Apply Settings".

Real-Time Installation of Updates:
1. System.
2. Software Management.
3. Live Update.
4. Under "Updates Configuration" click on each item and click "Real-Time" for the setting "Installation of Automatically Downloaded Updates".
5. Click "Save" for each item.

Check Contents

If the BIG-IP does not perform content filtering as part of its traffic management functionality, this is not applicable.

Note: Automatic signature updates can be configured, but depending on site connectivity this may not be possible. In this case manual upload of updates is possible. The below covers automatic update configuration.

Automatic Update Check:
From the BIG-IP GUI:
1. System.
2. Software Management.
3. Update Check.
4. Verify that "Automatic Update Check" is set to "Enabled".

Real-Time Installation of Updates:
1. System.
2. Software Management.
3. Live Update.
4. Under "Updates Configuration" click on each item and check that "Real-Time" is selected for the setting "Installation of Automatically Downloaded Updates".

If the BIG-IP appliance is not configured to automatically update malicious code protection mechanisms, this is a finding.

Vulnerability Number

V-266159

Documentable

False

Rule Version

F5BI-AP-300065

Severity Override Guidance

If the BIG-IP does not perform content filtering as part of its traffic management functionality, this is not applicable.

Note: Automatic signature updates can be configured, but depending on site connectivity this may not be possible. In this case manual upload of updates is possible. The below covers automatic update configuration.

Automatic Update Check:
From the BIG-IP GUI:
1. System.
2. Software Management.
3. Update Check.
4. Verify that "Automatic Update Check" is set to "Enabled".

Real-Time Installation of Updates:
1. System.
2. Software Management.
3. Live Update.
4. Under "Updates Configuration" click on each item and check that "Real-Time" is selected for the setting "Installation of Automatically Downloaded Updates".

If the BIG-IP appliance is not configured to automatically update malicious code protection mechanisms, this is a finding.

Check Content Reference

M

Target Key

5640