SV-266162r1024392_rule
V-266162
SRG-NET-000233-ALG-000115
F5BI-AP-300151
CAT III
10
When the Access Profile Type is LTM+APM and it is not using any connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, set the HTTP Only flag.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains.
6. Under Cookie Options, Check the box next to HTTP Only.
7. Click "Update".
8. Click "Apply Access Policy".
If the Access Profile Type is not LTM+APM and it uses connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, then this is not a finding.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains.
6. Under Cookie Options, verify HTTP Only is enabled.
If the F5 BIG-IP appliance does not enable the HTTP Only flag, this is a finding.
V-266162
False
F5BI-AP-300151
If the Access Profile Type is not LTM+APM and it uses connectivity resources (such as Network Access, Portal Access, etc.) in the VPE, then this is not a finding.
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains.
6. Under Cookie Options, verify HTTP Only is enabled.
If the F5 BIG-IP appliance does not enable the HTTP Only flag, this is a finding.
M
5640